Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Python | Python | 2.6.1 (including) | 2.6.1 (including) |
Python | Python | 2.6.2 (including) | 2.6.2 (including) |
Python | Python | 2.6.3 (including) | 2.6.3 (including) |
Python | Python | 2.6.4 (including) | 2.6.4 (including) |
Python | Python | 2.6.5 (including) | 2.6.5 (including) |
Python | Python | 2.6.6 (including) | 2.6.6 (including) |
Python | Python | 2.6.7 (including) | 2.6.7 (including) |
Python | Python | 2.6.8 (including) | 2.6.8 (including) |
Python | Python | 2.6.2150 (including) | 2.6.2150 (including) |
Python | Python | 2.6.6150 (including) | 2.6.6150 (including) |
Python | Python | 2.7.1 (including) | 2.7.1 (including) |
Python | Python | 2.7.1-rc1 (including) | 2.7.1-rc1 (including) |
Python | Python | 2.7.2-rc1 (including) | 2.7.2-rc1 (including) |
Python | Python | 2.7.3 (including) | 2.7.3 (including) |
Python | Python | 2.7.1150 (including) | 2.7.1150 (including) |
Python | Python | 2.7.2150 (including) | 2.7.2150 (including) |
Python | Python | 3.0 (including) | 3.0 (including) |
Python | Python | 3.0.1 (including) | 3.0.1 (including) |
Python | Python | 3.1 (including) | 3.1 (including) |
Python | Python | 3.1.1 (including) | 3.1.1 (including) |
Python | Python | 3.1.2 (including) | 3.1.2 (including) |
Python | Python | 3.1.3 (including) | 3.1.3 (including) |
Python | Python | 3.1.4 (including) | 3.1.4 (including) |
Python | Python | 3.1.5 (including) | 3.1.5 (including) |
Python | Python | 3.1.2150 (including) | 3.1.2150 (including) |
Python | Python | 3.2 (including) | 3.2 (including) |
Python | Python | 3.2-alpha (including) | 3.2-alpha (including) |