CVE Vulnerabilities

CVE-2011-4944

Published: Aug 27, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
1.2 LOW
AV:L/AC:H/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

Affected Software

NameVendorStart VersionEnd Version
PythonPython2.6.1 (including)2.6.1 (including)
PythonPython2.6.2 (including)2.6.2 (including)
PythonPython2.6.3 (including)2.6.3 (including)
PythonPython2.6.4 (including)2.6.4 (including)
PythonPython2.6.5 (including)2.6.5 (including)
PythonPython2.6.6 (including)2.6.6 (including)
PythonPython2.6.7 (including)2.6.7 (including)
PythonPython2.6.8 (including)2.6.8 (including)
PythonPython2.6.2150 (including)2.6.2150 (including)
PythonPython2.6.6150 (including)2.6.6150 (including)
PythonPython2.7.1 (including)2.7.1 (including)
PythonPython2.7.1-rc1 (including)2.7.1-rc1 (including)
PythonPython2.7.2-rc1 (including)2.7.2-rc1 (including)
PythonPython2.7.3 (including)2.7.3 (including)
PythonPython2.7.1150 (including)2.7.1150 (including)
PythonPython2.7.2150 (including)2.7.2150 (including)
PythonPython3.0 (including)3.0 (including)
PythonPython3.0.1 (including)3.0.1 (including)
PythonPython3.1 (including)3.1 (including)
PythonPython3.1.1 (including)3.1.1 (including)
PythonPython3.1.2 (including)3.1.2 (including)
PythonPython3.1.3 (including)3.1.3 (including)
PythonPython3.1.4 (including)3.1.4 (including)
PythonPython3.1.5 (including)3.1.5 (including)
PythonPython3.1.2150 (including)3.1.2150 (including)
PythonPython3.2 (including)3.2 (including)
PythonPython3.2-alpha (including)3.2-alpha (including)
Red Hat Enterprise Linux 5RedHatpython-0:2.4.3-46.el5_8.2*
Red Hat Enterprise Linux 6RedHatpython-0:2.6.6-29.el6_2.2*
Python2.4Ubuntuhardy*
Python2.4Ubuntuupstream*
Python2.5Ubuntuhardy*
Python2.5Ubuntuupstream*
Python2.6Ubuntulucid*
Python2.6Ubuntumaverick*
Python2.6Ubuntunatty*
Python2.6Ubuntuoneiric*
Python2.6Ubuntuupstream*
Python2.7Ubuntumaverick*
Python2.7Ubuntunatty*
Python2.7Ubuntuoneiric*
Python2.7Ubuntuupstream*
Python3.1Ubuntulucid*
Python3.1Ubuntumaverick*
Python3.1Ubuntunatty*
Python3.1Ubuntuupstream*
Python3.2Ubuntunatty*
Python3.2Ubuntuoneiric*
Python3.2Ubuntuprecise*
Python3.2Ubuntuquantal*
Python3.2Ubuntuupstream*
Python3.3Ubuntuupstream*

References