Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-1629
HistoryAug 06, 2013 - 12:00 a.m.

CVE-2013-1629

2013-08-0600:00:00
ubuntu.com
ubuntu.com
19

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.004

Percentile

73.0%

pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and
does not perform integrity checks on package contents, which allows
man-in-the-middle attackers to execute arbitrary code via a crafted
response to a “pip install” operation.

Bugs

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.004

Percentile

73.0%