| From: |
| Mageia Updates <buildsystem-daemon@mageia.org> |
| To: |
| updates-announce@ml.mageia.org |
| Subject: |
| [updates-announce] MGASA-2013-0274: Updated python-setuptools and python-virtualenv packages fix security vulnerability |
| Date: |
| Fri, 13 Sep 2013 22:13:16 +0200 |
| Message-ID: |
| <20130913201316.CEB1C489B4@valstar.mageia.org> |
| Archive-link: |
| Article, Thread
|
MGASA-2013-0274 - Updated python-setuptools and python-virtualenv packages fix security
vulnerability
Publication date: 13 Sep 2013
URL: http://advisories.mageia.org/MGASA-2013-0274.html
Type: security
Affected Mageia releases: 2, 3
CVE: CVE-2013-1633
Description:
easy_install in setuptools before 0.7 uses HTTP to retrieve packages from
the PyPI repository, and does not perform integrity checks on package
contents, which allows man-in-the-middle attackers to execute arbitrary
code via a crafted response to the default use of the product
(CVE-2013-1633).
References:
- https://bugs.mageia.org/show_bug.cgi?id=11169
- https://lists.fedoraproject.org/pipermail/package-announc...
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1633
SRPMS:
- 3/core/python-setuptools-0.9.8-2.1.mga3
- 3/core/python-virtualenv-1.10.1-1.1.mga3
- 2/core/python-setuptools-0.9.8-1.1.mga2
- 2/core/python-virtualenv-1.10.1-0.1.mga2
(
Log in to post comments)