Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-1633

Опубликовано: 06 авг. 2013
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:python:setuptools:*:*:*:*:*:*:*:*
Версия до 0.7b4 (включая)
cpe:2.3:a:python:setuptools:0.6.40:*:*:*:*:*:*:*
cpe:2.3:a:python:setuptools:0.6.41:*:*:*:*:*:*:*
cpe:2.3:a:python:setuptools:0.6.42:*:*:*:*:*:*:*
cpe:2.3:a:python:setuptools:0.6.43:*:*:*:*:*:*:*
cpe:2.3:a:python:setuptools:0.6.44:*:*:*:*:*:*:*
cpe:2.3:a:python:setuptools:0.6.45:*:*:*:*:*:*:*
cpe:2.3:a:python:setuptools:0.6.46:*:*:*:*:*:*:*
cpe:2.3:a:python:setuptools:0.6.47:*:*:*:*:*:*:*
cpe:2.3:a:python:setuptools:0.6.48:*:*:*:*:*:*:*
cpe:2.3:a:python:setuptools:0.6.49:*:*:*:*:*:*:*

EPSS

Процентиль: 73%
0.00765
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 12 лет назад

easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

redhat
больше 12 лет назад

easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

debian
больше 12 лет назад

easy_install in setuptools before 0.7 uses HTTP to retrieve packages f ...

CVSS3: 8.3
github
больше 3 лет назад

Setuptools vulnerable to Man-in-the-middle attacks

EPSS

Процентиль: 73%
0.00765
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-20