Arbitrary Code Execution Affecting setuptools package, versions [,0.7)
Threat Intelligence
EPSS
0.15% (53rd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-SETUPTOOLS-40178
- published 24 Feb 2016
- disclosed 6 Aug 2013
- credit Unknown
Overview
setuptools
is a Easily download, build, install, upgrade, and uninstall Python packages
easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.
References
CVSS Scores
version 3.1