|
|
| |
|
| |
python-virtualenv: code execution
| Package(s): | python-virtualenv |
CVE #(s): | CVE-2013-1633
|
| Created: | September 5, 2013 |
Updated: | September 18, 2013 |
| Description: |
From the Red Hat bugzilla entry:
easy_install in setuptools before 0.7 uses HTTP to retrieve packages
from the PyPI repository, and does not perform integrity checks on
package contents, which allows man-in-the-middle attackers to execute
arbitrary code via a crafted response to the default use of the
product. |
| Alerts: |
|
( Log in to post comments)
|
|
|