CVE Vulnerabilities

CVE-2011-4944

Published: Aug 27, 2012 | Modified: Oct 25, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

Affected Software

Name Vendor Start Version End Version
Python Python 2.6.1 (including) 2.6.1 (including)
Python Python 2.6.2 (including) 2.6.2 (including)
Python Python 2.6.3 (including) 2.6.3 (including)
Python Python 2.6.4 (including) 2.6.4 (including)
Python Python 2.6.5 (including) 2.6.5 (including)
Python Python 2.6.6 (including) 2.6.6 (including)
Python Python 2.6.7 (including) 2.6.7 (including)
Python Python 2.6.8 (including) 2.6.8 (including)
Python Python 2.6.2150 (including) 2.6.2150 (including)
Python Python 2.6.6150 (including) 2.6.6150 (including)
Python Python 2.7.1 (including) 2.7.1 (including)
Python Python 2.7.1-rc1 (including) 2.7.1-rc1 (including)
Python Python 2.7.2-rc1 (including) 2.7.2-rc1 (including)
Python Python 2.7.3 (including) 2.7.3 (including)
Python Python 2.7.1150 (including) 2.7.1150 (including)
Python Python 2.7.2150 (including) 2.7.2150 (including)
Python Python 3.0 (including) 3.0 (including)
Python Python 3.0.1 (including) 3.0.1 (including)
Python Python 3.1 (including) 3.1 (including)
Python Python 3.1.1 (including) 3.1.1 (including)
Python Python 3.1.2 (including) 3.1.2 (including)
Python Python 3.1.3 (including) 3.1.3 (including)
Python Python 3.1.4 (including) 3.1.4 (including)
Python Python 3.1.5 (including) 3.1.5 (including)
Python Python 3.1.2150 (including) 3.1.2150 (including)
Python Python 3.2 (including) 3.2 (including)
Python Python 3.2-alpha (including) 3.2-alpha (including)

References