pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "8.1.1-2ubuntu0.4", "binary_name": "python-pip" }, { "binary_version": "8.1.1-2ubuntu0.4", "binary_name": "python-pip-whl" }, { "binary_version": "8.1.1-2ubuntu0.4", "binary_name": "python3-pip" } ] }