CVE-2013-1629
06.08.2013, 02:52
pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.Enginsight
Vendor | Product | Version |
---|---|---|
pypa | pip | 𝑥 < 1.3 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
python-pip |
| ||||||||||||||||||||||||||||
python-virtualenv |
|
Common Weakness Enumeration
References