Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.
2012-08-27T23:55:01.290
2025-04-11T00:51:21.963
Deferred
CVSSv2: 1.9 (LOW)
AV:L/AC:M/Au:N/C:P/I:N/A:N
3.4
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | python | python | 2.6.1 | Yes |
Application | python | python | 2.6.2 | Yes |
Application | python | python | 2.6.3 | Yes |
Application | python | python | 2.6.4 | Yes |
Application | python | python | 2.6.5 | Yes |
Application | python | python | 2.6.6 | Yes |
Application | python | python | 2.6.7 | Yes |
Application | python | python | 2.6.8 | Yes |
Application | python | python | 2.6.2150 | Yes |
Application | python | python | 2.6.6150 | Yes |
Application | python | python | 2.7.1 | Yes |
Application | python | python | 2.7.1 | Yes |
Application | python | python | 2.7.2 | Yes |
Application | python | python | 2.7.3 | Yes |
Application | python | python | 2.7.1150 | Yes |
Application | python | python | 2.7.1150 | Yes |
Application | python | python | 2.7.2150 | Yes |
Application | python | python | 3.0 | Yes |
Application | python | python | 3.0.1 | Yes |
Application | python | python | 3.1 | Yes |
Application | python | python | 3.1.1 | Yes |
Application | python | python | 3.1.2 | Yes |
Application | python | python | 3.1.3 | Yes |
Application | python | python | 3.1.4 | Yes |
Application | python | python | 3.1.5 | Yes |
Application | python | python | 3.1.2150 | Yes |
Application | python | python | 3.2 | Yes |
Application | python | python | 3.2 | Yes |