Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-4944

Опубликовано: 30 нояб. 2011
Источник: redhat
CVSS2: 1.2

Описание

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

Отчет

The Red Hat Security Response Team has rated this issue as having low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4pythonWill not fix
Red Hat Enterprise Linux 5pythonFixedRHSA-2012:074518.06.2012
Red Hat Enterprise Linux 6pythonFixedRHSA-2012:074418.06.2012

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=758905python: distutils creates ~/.pypirc insecurely

1.2 Low

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

nvd
почти 13 лет назад

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

debian
почти 13 лет назад

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissio ...

github
около 3 лет назад

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

oracle-oval
около 13 лет назад

ELSA-2012-0745: python security update (MODERATE)

1.2 Low

CVSS2

Уязвимость CVE-2011-4944