Total vulnerabilities in the database
easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.
Software | From | Fixed in |
---|---|---|
python / setuptools | - | 0.7b4.x |
python / setuptools | 0.6.46 | 0.6.46.x |
python / setuptools | 0.6.41 | 0.6.41.x |
python / setuptools | 0.6.42 | 0.6.42.x |
python / setuptools | 0.6.47 | 0.6.47.x |
python / setuptools | 0.6.48 | 0.6.48.x |
python / setuptools | 0.6.49 | 0.6.49.x |
python / setuptools | 0.6.44 | 0.6.44.x |
python / setuptools | 0.6.43 | 0.6.43.x |
python / setuptools | 0.6.45 | 0.6.45.x |
python / setuptools | 0.6.40 | 0.6.40.x |