6.8
CVSSv2

CVE-2013-1629

Published: 06/08/2013 Updated: 15/03/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 606
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

pip prior to 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle malicious users to execute arbitrary code via a crafted response to a "pip install" operation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pypa pip

Vendor Advisories

Debian Bug report logs - #710163 CVE-2013-1629: Man in the middle possibility Package: python-pip; Maintainer for python-pip is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Source for python-pip is src:python-pip (PTS, buildd, popcon) Reported by: Micah Anderson <micah@debianorg> Date: T ...