PYSEC-2013-10

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/pyshop/PYSEC-2013-10.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2013-10
Aliases
Published
2013-08-06T02:52:00Z
Modified
2024-04-30T15:11:51.575998Z
Summary
[none]
Details

pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a download operation.

References

Affected packages

PyPI / pyshop

Package

Affected ranges

Type
GIT
Repo
https://github.com/mardiros/pyshop
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.7.1

Affected versions

0.*
0.1
0.2
0.3
0.4
0.5
0.6
0.7

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/pyshop/PYSEC-2013-10.yaml"