6.8
CVSSv2

CVE-2013-1633

Published: 06/08/2013 Updated: 11/10/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

easy_install in setuptools prior to 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle malicious users to execute arbitrary code via a crafted response to the default use of the product.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

python setuptools 0.6.44

python setuptools 0.6.46

python setuptools 0.6.48

python setuptools

python setuptools 0.6.43

python setuptools 0.6.40

python setuptools 0.6.49

python setuptools 0.6.47

python setuptools 0.6.45

python setuptools 0.6.41

python setuptools 0.6.42

Vendor Advisories

easy_install in setuptools before 07 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product ...