---
title: "CVE-2014-8991\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-8991?format=md
keywords: index, follow
---

# CVE-2014-8991

Publication date 24 November 2014

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

pip 1.3 through 1.5.6 allows local users to cause a denial of service
(prevention of package installation) by creating a /tmp/pip-build-\* file
for another user.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2014-8991?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| python-pip | 18.04 LTS bionic | Not affected |
| 17.10 artful | Not affected |
| 17.04 zesty | Ignored end of life |
| 16.10 yakkety | Ignored end of life |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Ignored end of life |
| 15.04 vivid | Ignored end of life |
| 14.10 utopic | Ignored end of life |
| 14.04 LTS trusty | Ignored end of standard support |
| 12.04 LTS precise | Ignored end of life |
| 10.04 LTS lucid | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [msalvatore](https://launchpad.net/~msalvatore)

The patch from upstream does not resolve the CVE. Backporting this
the actual fix for trusty requires invasive changes that will
change the command line interface. The issues is first fixed in
version 7.0.0 and the changelog mentions it is backwards
incompatible.

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8991)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-8991)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-8991)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-8991)

### Other references

* <https://github.com/pypa/pip/pull/2122>
* <https://www.cve.org/CVERecord?id=CVE-2014-8991>
