Описание
pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| python-pip | fixed | 1.3.1-1 | package | |
| python-pip | no-dsa | wheezy | package | |
| python-pip | no-dsa | squeeze | package | |
| python-virtualenv | fixed | 1.9.1-1 | package | |
| python-virtualenv | no-dsa | wheezy | package | |
| python-virtualenv | no-dsa | squeeze | package |
EPSS
Связанные уязвимости
pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.
pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.
EPSS