CVE-2013-1633
Last modified
CVE-2013-1633 is a vulnerability of currently unknown severity. easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.. EPSS estimates a 1.95% chance of exploitation in the next 30 days.
Description
easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Python | Setuptools | <= 0.7b4 |
| Python | Setuptools | 0.6.40 |
| Python | Setuptools | 0.6.41 |
| Python | Setuptools | 0.6.42 |
| Python | Setuptools | 0.6.43 |
| Python | Setuptools | 0.6.44 |
| Python | Setuptools | 0.6.45 |
| Python | Setuptools | 0.6.46 |
| Python | Setuptools | 0.6.47 |
| Python | Setuptools | 0.6.48 |
| Python | Setuptools | 0.6.49 |
References
- https://pypi.python.org/pypi/setuptools/0.9.8#changesVendor Advisory
- https://pypi.python.org/pypi/setuptools/0.9.8#changesVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-1633?
How severe is CVE-2013-1633?
How do I fix CVE-2013-1633?
Are you affected by CVE-2013-1633?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
