[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2013:227 -- Mandriva python-setuptools

ID: oval:org.secpod.oval:def:1300229Date: (C)2013-11-01   (M)2022-10-10
Class: PATCHFamily: unix




A vulnerability has been discovered and corrected in python-setuptools/python-virtualenv: easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product . The updated python-setuptools packages has been upgraded to the 0.9.8 version and the python-virtualenv packages has been upgraded to the 1.10.1 version which is not vulnerable to this issue.

Platform:
Mandriva Enterprise Server 5.2
Product:
python-setuptools
Reference:
MDVSA-2013:227
CVE-2013-1633
CVE    1
CVE-2013-1633
CPE    1
cpe:/o:mandriva:enterprise_server:5.2

© SecPod Technologies