CVE-2013-1629
06.08.2013, 02:52
pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.Enginsight
| Vendor | Product | Version |
|---|---|---|
| pypa | pip | 𝑥 < 1.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python-pip |
| ||||||||||||||||||||||||||||
| python-virtualenv |
|
Common Weakness Enumeration
References