Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-5123

Опубликовано: 05 нояб. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 5.9

Описание

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

РелизСтатусПримечание
artful

not-affected

bionic

not-affected

devel

not-affected

esm-apps-legacy/xenial

not-affected

8.1.1-2ubuntu0.4
esm-apps/bionic

not-affected

esm-apps/xenial

not-affected

8.1.1-2ubuntu0.4
esm-infra-legacy/trusty

not-affected

1.5.4-1ubuntu4
lucid

ignored

end of life, was deferred
precise

ignored

end of life
precise/esm

DNE

precise was deferred [2013-08-22]

Показывать по

EPSS

Процентиль: 94%
0.07987
Низкий

4.3 Medium

CVSS2

5.9 Medium

CVSS3

Связанные уязвимости

redhat
около 13 лет назад

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

CVSS3: 5.9
nvd
почти 7 лет назад

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

CVSS3: 5.9
debian
почти 7 лет назад

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 use ...

CVSS3: 5.9
github
около 4 лет назад

Improper Authentication in pip

suse-cvrf
почти 7 лет назад

Recommended update for python-jmespath, python-jsonschema, python-paramiko, python-pexpect, python-pip, python-ply, python-pretend, python-process-tests, python-pycodestyle, python-pyflakes, python-pyxdg, python-tabulate, python-vcversioner

EPSS

Процентиль: 94%
0.07987
Низкий

4.3 Medium

CVSS2

5.9 Medium

CVSS3