First published: Tue Aug 06 2013(Updated: )
easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/setuptools | <0.7 | 0.7 |
Python Setuptools | <=0.7b4 | |
Python Setuptools | =0.6.40 | |
Python Setuptools | =0.6.41 | |
Python Setuptools | =0.6.42 | |
Python Setuptools | =0.6.43 | |
Python Setuptools | =0.6.44 | |
Python Setuptools | =0.6.45 | |
Python Setuptools | =0.6.46 | |
Python Setuptools | =0.6.47 | |
Python Setuptools | =0.6.48 | |
Python Setuptools | =0.6.49 | |
<=0.7b4 | ||
=0.6.40 | ||
=0.6.41 | ||
=0.6.42 | ||
=0.6.43 | ||
=0.6.44 | ||
=0.6.45 | ||
=0.6.46 | ||
=0.6.47 | ||
=0.6.48 | ||
=0.6.49 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.