pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.
{ "binaries": [ { "binary_name": "python-pip", "binary_version": "1.5.4-1ubuntu4+esm5" }, { "binary_name": "python-pip-whl", "binary_version": "1.5.4-1ubuntu4+esm5" }, { "binary_name": "python3-pip", "binary_version": "1.5.4-1ubuntu4+esm5" } ] }