CVE-2013-1633
06.08.2013, 02:52
easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.Enginsight
Vendor | Product | Version |
---|---|---|
python | setuptools | 𝑥 ≤ 0.7b4 |
python | setuptools | 0.6.40 |
python | setuptools | 0.6.41 |
python | setuptools | 0.6.42 |
python | setuptools | 0.6.43 |
python | setuptools | 0.6.44 |
python | setuptools | 0.6.45 |
python | setuptools | 0.6.46 |
python | setuptools | 0.6.47 |
python | setuptools | 0.6.48 |
python | setuptools | 0.6.49 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References