← Back

CVE-2013-1633

nvd nist
Published: Aug 6, 2013Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

Affected (11)

Products: Python: Setuptools
1 product
Setuptools
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Python
Up to 0.7b4
Version 0.6.40
Version 0.6.41
Version 0.6.42
Version 0.6.43
Version 0.6.44
Version 0.6.45
Version 0.6.46
Version 0.6.47
Version 0.6.48
Version 0.6.49

Timeline

No history available yet.