CVE-2013-5123
05.11.2019, 22:15
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.Enginsight
Vendor | Product | Version |
---|---|---|
pypa | pip | 𝑥 < 1.5 |
virtualenv | virtualenv | 12.0.7 |
redhat | openshift | 1.0 |
redhat | openshift | 2.0 |
redhat | software_collections | - |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References