LWN.net Logo

python-virtualenv: code execution

Package(s):python-virtualenv CVE #(s):CVE-2013-1633
Created:September 5, 2013 Updated:September 18, 2013
Description:

From the Red Hat bugzilla entry:

easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

Alerts:
Fedora FEDORA-2013-14891 2013-09-05
Fedora FEDORA-2013-14902 2013-09-05
Mandriva MDVSA-2013:227 2013-09-09
Mageia MGASA-2013-0274 2013-09-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds