LWN.net Logo

pip: code execution

Package(s):pip CVE #(s):CVE-2013-1629
Created:September 13, 2013 Updated:September 18, 2013
Description:

From the CVE entry:

pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.

Alerts:
Gentoo 201309-05 2013-09-12

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds