Unauthorized File Access Affecting python package, versions [,2.7.17)[3.0.0,3.5.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Not Defined
EPSS
0.06% (29th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-PYTHON-2317729
  • published14 Dec 2021
  • disclosed8 Jul 2019
  • creditUnknown

Introduced: 8 Jul 2019

CVE-2019-13404  (opens in a new tab)
CWE-552  (opens in a new tab)

How to fix?

Upgrade python to version 2.7.17, 3.5.0 or higher.

Overview

Affected versions of this package are vulnerable to Unauthorized File Access. ** DISPUTED ** The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects old 3.x releases before 3.5.) NOTE: the vendor's position is that it is the user's responsibility to ensure C:\Python27 access control or choose a different directory, because backwards compatibility requires that C:\Python27 remain the default for 2.7.x.

References

CVSS Scores

version 3.1