CVE-2013-1630 Information

Description

pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository and does not perform integrity checks on package contents which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a download operation.

Reference

http://www.reddit.com/r/Python/comments/17rfh7/warning_dont_use_pip_in_an_untrusted_network_a/ https://github.com/mardiros/pyshop/blob/master/CHANGES.txt https://github.com/mardiros/pyshop/commit/ffadb0bcdef1e385884571670210cfd6ba351784

Share on: