CVE-2013-5123

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
Affected Products (NVD)
VendorProductVersion
pypapip
𝑥
< 1.5
virtualenvvirtualenv
12.0.7
redhatopenshift
1.0
redhatopenshift
2.0
redhatsoftware_collections
-
debiandebian_linux
8.0
debiandebian_linux
9.0
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python-pip
bookworm
23.0.1+dfsg-1
fixed
bullseye
20.3.4-4+deb11u1
fixed
sid
24.3.1+dfsg-1
fixed
squeeze
not-affected
trixie
24.3.1+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-pip
artful
not-affected
bionic
not-affected
lucid
ignored
precise
ignored
quantal
ignored
raring
ignored
saucy
ignored
trusty
not-affected
utopic
ignored
vivid
ignored
wily
ignored
xenial
not-affected
yakkety
ignored
zesty
ignored
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
aws-cli-py36
suse enterprise server 12 SP3
1.19.9-6.3.15
fixed
libpython3_6m1_0
suse enterprise server 12 SP3
3.6.15-6.61.5
fixed
python-jmespath
suse enterprise sap 12
0.9.2-10.6.1
fixed
suse enterprise sap 12 SP3
0.9.2-10.6.1
fixed
suse enterprise sap 12 SP4
0.9.2-10.6.1
fixed
suse enterprise sap 12 SP5
0.9.2-10.6.1
fixed
suse enterprise server 12
0.9.2-10.6.1
fixed
suse enterprise server 12 SP3
0.9.2-10.6.1
fixed
suse enterprise server 12 SP4
0.9.2-10.6.1
fixed
suse enterprise server 12 SP5
0.9.2-10.6.1
fixed
python-jsonschema
suse enterprise sap 12
2.2.0-3.3.1
fixed
suse enterprise sap 12 SP3
2.2.0-3.3.1
fixed
suse enterprise sap 12 SP4
2.2.0-3.3.1
fixed
suse enterprise sap 12 SP5
2.2.0-3.3.1
fixed
suse enterprise server 12
2.2.0-3.3.1
fixed
suse enterprise server 12 SP3
2.2.0-3.3.1
fixed
suse enterprise server 12 SP4
2.2.0-3.3.1
fixed
suse enterprise server 12 SP5
2.2.0-3.3.1
fixed
python-paramiko
suse enterprise sap 12
1.18.5-2.15.1
fixed
suse enterprise sap 12 SP3
1.18.5-2.15.1
fixed
suse enterprise sap 12 SP4
1.18.5-2.15.1
fixed
suse enterprise sap 12 SP5
1.18.5-2.15.1
fixed
suse enterprise server 12
1.18.5-2.15.1
fixed
suse enterprise server 12 SP3
1.18.5-2.15.1
fixed
suse enterprise server 12 SP4
1.18.5-2.15.1
fixed
suse enterprise server 12 SP5
1.18.5-2.15.1
fixed
python-pip
suse enterprise sap 12
10.0.1-11.6.1
fixed
suse enterprise sap 12 SP3
10.0.1-11.6.1
fixed
suse enterprise sap 12 SP4
10.0.1-11.6.1
fixed
suse enterprise sap 12 SP5
10.0.1-11.6.1
fixed
suse enterprise server 12
10.0.1-11.6.1
fixed
suse enterprise server 12 SP3
10.0.1-11.6.1
fixed
suse enterprise server 12 SP4
10.0.1-11.6.1
fixed
suse enterprise server 12 SP5
10.0.1-11.6.1
fixed
python-ply
suse enterprise sap 12
3.4-3.3.1
fixed
suse enterprise sap 12 SP3
3.4-3.3.1
fixed
suse enterprise sap 12 SP4
3.4-3.3.1
fixed
suse enterprise sap 12 SP5
3.4-3.3.1
fixed
suse enterprise server 12
3.4-3.3.1
fixed
suse enterprise server 12 SP3
3.4-3.3.1
fixed
suse enterprise server 12 SP4
3.4-3.3.1
fixed
suse enterprise server 12 SP5
3.4-3.3.1
fixed
python2-pip
suse enterprise desktop 15
10.0.1-1.9
fixed
suse enterprise sap 15
10.0.1-1.9
fixed
suse enterprise server 15
10.0.1-1.9
fixed
python3-jmespath
suse enterprise sap 12
0.9.2-10.6.1
fixed
suse enterprise sap 12 SP3
0.9.2-10.6.1
fixed
suse enterprise sap 12 SP4
0.9.2-10.6.1
fixed
suse enterprise sap 12 SP5
0.9.2-10.6.1
fixed
suse enterprise server 12
0.9.2-10.6.1
fixed
suse enterprise server 12 SP3
0.9.2-10.6.1
fixed
suse enterprise server 12 SP4
0.9.2-10.6.1
fixed
suse enterprise server 12 SP5
0.9.2-10.6.1
fixed
python3-jsonschema
suse enterprise sap 12
2.2.0-3.3.1
fixed
suse enterprise sap 12 SP3
2.2.0-3.3.1
fixed
suse enterprise sap 12 SP4
2.2.0-3.3.1
fixed
suse enterprise sap 12 SP5
2.2.0-3.3.1
fixed
suse enterprise server 12
2.2.0-3.3.1
fixed
suse enterprise server 12 SP3
2.2.0-3.3.1
fixed
suse enterprise server 12 SP4
2.2.0-3.3.1
fixed
suse enterprise server 12 SP5
2.2.0-3.3.1
fixed
python3-paramiko
suse enterprise sap 12
1.18.5-2.15.1
fixed
suse enterprise sap 12 SP3
1.18.5-2.15.1
fixed
suse enterprise sap 12 SP4
1.18.5-2.15.1
fixed
suse enterprise sap 12 SP5
1.18.5-2.15.1
fixed
suse enterprise server 12
1.18.5-2.15.1
fixed
suse enterprise server 12 SP3
1.18.5-2.15.1
fixed
suse enterprise server 12 SP4
1.18.5-2.15.1
fixed
suse enterprise server 12 SP5
1.18.5-2.15.1
fixed
python3-pip
suse enterprise desktop 15
10.0.1-1.9
fixed
suse enterprise sap 12
10.0.1-11.6.1
fixed
suse enterprise sap 12 SP3
10.0.1-11.6.1
fixed
suse enterprise sap 12 SP4
10.0.1-11.6.1
fixed
suse enterprise sap 12 SP5
10.0.1-11.6.1
fixed
suse enterprise sap 15
10.0.1-1.9
fixed
suse enterprise server 12
10.0.1-11.6.1
fixed
suse enterprise server 12 SP3
10.0.1-11.6.1
fixed
suse enterprise server 12 SP4
10.0.1-11.6.1
fixed
suse enterprise server 12 SP5
10.0.1-11.6.1
fixed
suse enterprise server 15
10.0.1-1.9
fixed
python3-ply
suse enterprise sap 12
3.4-3.3.1
fixed
suse enterprise sap 12 SP3
3.4-3.3.1
fixed
suse enterprise sap 12 SP4
3.4-3.3.1
fixed
suse enterprise sap 12 SP5
3.4-3.3.1
fixed
suse enterprise server 12
3.4-3.3.1
fixed
suse enterprise server 12 SP3
3.4-3.3.1
fixed
suse enterprise server 12 SP4
3.4-3.3.1
fixed
suse enterprise server 12 SP5
3.4-3.3.1
fixed
python36
suse enterprise server 12 SP3
3.6.15-6.61.6
fixed
python36-PyYAML
suse enterprise server 12 SP3
5.3.1-6.5.12
fixed
python36-appdirs
suse enterprise server 12 SP3
1.4.3-6.3.8
fixed
python36-asn1crypto
suse enterprise server 12 SP3
0.24.0-6.3.16
fixed
python36-base
suse enterprise server 12 SP3
3.6.15-6.61.5
fixed
python36-boto3
suse enterprise server 12 SP3
1.17.9-6.3.11
fixed
python36-botocore
suse enterprise server 12 SP3
1.20.9-6.3.11
fixed
python36-certifi
suse enterprise server 12 SP3
2018.1.18-6.3.15
fixed
python36-cffi
suse enterprise server 12 SP3
1.11.5-6.3.18
fixed
python36-chardet
suse enterprise server 12 SP3
3.0.4-6.3.15
fixed
python36-colorama
suse enterprise server 12 SP3
0.4.4-6.3.15
fixed
python36-cryptography
suse enterprise server 12 SP3
2.8-6.3.17
fixed
python36-curses
suse enterprise server 12 SP3
3.6.15-6.61.6
fixed
python36-dbm
suse enterprise server 12 SP3
3.6.15-6.61.6
fixed
python36-devel
suse enterprise server 12 SP3
3.6.15-6.61.5
fixed
python36-docutils
suse enterprise server 12 SP3
0.14-6.3.8
fixed
python36-idle
suse enterprise server 12 SP3
3.6.15-6.61.6
fixed
python36-idna
suse enterprise server 12 SP3
2.6-6.5.15
fixed
python36-jmespath
suse enterprise server 12 SP3
0.9.3-6.3.14
fixed
python36-packaging
suse enterprise server 12 SP3
17.1-6.6.8
fixed
python36-ply
suse enterprise server 12 SP3
3.10-6.3.8
fixed
python36-ply-doc
suse enterprise server 12 SP3
3.10-6.3.8
fixed
python36-py
suse enterprise server 12 SP3
1.8.1-6.3.15
fixed
python36-pyOpenSSL
suse enterprise server 12 SP3
17.1.0-6.3.16
fixed
python36-pyasn1
suse enterprise server 12 SP3
0.1.9-6.3.18
fixed
python36-pycparser
suse enterprise server 12 SP3
2.10-6.3.9
fixed
python36-pyparsing
suse enterprise server 12 SP3
2.4.7-6.3.9
fixed
python36-pyparsing-doc
suse enterprise server 12 SP3
2.4.7-6.3.9
fixed
python36-python-dateutil
suse enterprise server 12 SP3
2.7.3-6.3.13
fixed
python36-requests
suse enterprise server 12 SP3
2.24.0-6.3.15
fixed
python36-rsa
suse enterprise server 12 SP3
3.4.2-6.3.15
fixed
python36-s3transfer
suse enterprise server 12 SP3
0.3.3-6.3.11
fixed
python36-setuptools
suse enterprise server 12 SP3
44.1.1-9.11.1
fixed
python36-setuptools-test
suse enterprise server 12 SP3
44.1.1-6.7.4
fixed
python36-setuptools-wheel
suse enterprise server 12 SP3
44.1.1-6.7.3
fixed
python36-simplejson
suse enterprise server 12 SP3
3.8.2-6.3.16
fixed
python36-six
suse enterprise server 12 SP3
1.14.0-6.7.3
fixed
python36-six-doc
suse enterprise server 12 SP3
1.14.0-6.7.6
fixed
python36-testsuite
suse enterprise server 12 SP3
3.6.15-6.61.5
fixed
python36-tk
suse enterprise server 12 SP3
3.6.15-6.61.6
fixed
python36-tools
suse enterprise server 12 SP3
3.6.15-6.61.5
fixed
python36-urllib3
suse enterprise server 12 SP3
1.25.10-6.3.13
fixed
python39-pip
suse enterprise desktop 15 SP3
20.2.4-7.5.1
fixed
suse enterprise sap 15 SP3
20.2.4-7.5.1
fixed
suse enterprise server 15 SP3
20.2.4-7.5.1
fixed
python39-setuptools
suse enterprise desktop 15 SP3
44.1.1-7.3.1
fixed
suse enterprise sap 15 SP3
44.1.1-7.3.1
fixed
suse enterprise server 15 SP3
44.1.1-7.3.1
fixed