Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2013-1629
HistoryAug 06, 2013 - 2:52 a.m.

CVE-2013-1629

2013-08-0602:52:10
Debian Security Bug Tracker
security-tracker.debian.org
15
cve-2013-1629
pypi repository
http
integrity checks
man-in-the-middle
arbitrary code
pip install
unix

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.004

Percentile

73.0%

pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a “pip install” operation.

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.004

Percentile

73.0%