Lucene search

K
cvelistMitreCVELIST:CVE-2013-1633
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-1633

2022-10-0316:14:47
mitre
www.cve.org
2
easy_install
setuptools
pypi
integrity checks
man-in-the-middle
arbitrary code

7 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

51.7%

easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

7 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

51.7%