Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Python | Python | 2.6.1 | 2.6.1 |
Python | Python | 2.6.2 | 2.6.2 |
Python | Python | 2.6.3 | 2.6.3 |
Python | Python | 2.6.4 | 2.6.4 |
Python | Python | 2.6.5 | 2.6.5 |
Python | Python | 2.6.6 | 2.6.6 |
Python | Python | 2.6.7 | 2.6.7 |
Python | Python | 2.6.8 | 2.6.8 |
Python | Python | 2.6.2150 | 2.6.2150 |
Python | Python | 2.6.6150 | 2.6.6150 |
Python | Python | 2.7.1 | 2.7.1 |
Python | Python | 2.7.1 | 2.7.1 |
Python | Python | 2.7.2 | 2.7.2 |
Python | Python | 2.7.3 | 2.7.3 |
Python | Python | 2.7.1150 | 2.7.1150 |
Python | Python | 2.7.1150 | 2.7.1150 |
Python | Python | 2.7.2150 | 2.7.2150 |
Python | Python | 3.0 | 3.0 |
Python | Python | 3.0.1 | 3.0.1 |
Python | Python | 3.1 | 3.1 |
Python | Python | 3.1.1 | 3.1.1 |
Python | Python | 3.1.2 | 3.1.2 |
Python | Python | 3.1.3 | 3.1.3 |
Python | Python | 3.1.4 | 3.1.4 |
Python | Python | 3.1.5 | 3.1.5 |
Python | Python | 3.1.2150 | 3.1.2150 |
Python | Python | 3.2 | 3.2 |
Python | Python | 3.2 | 3.2 |
Red Hat Enterprise Linux 5 | RedHat | python-0:2.4.3-46.el5_8.2 | * |
Red Hat Enterprise Linux 6 | RedHat | python-0:2.6.6-29.el6_2.2 | * |
Python2.4 | Ubuntu | hardy | * |
Python2.4 | Ubuntu | upstream | * |
Python2.5 | Ubuntu | hardy | * |
Python2.5 | Ubuntu | upstream | * |
Python2.6 | Ubuntu | lucid | * |
Python2.6 | Ubuntu | maverick | * |
Python2.6 | Ubuntu | natty | * |
Python2.6 | Ubuntu | oneiric | * |
Python2.6 | Ubuntu | upstream | * |
Python2.7 | Ubuntu | maverick | * |
Python2.7 | Ubuntu | natty | * |
Python2.7 | Ubuntu | oneiric | * |
Python2.7 | Ubuntu | upstream | * |
Python3.1 | Ubuntu | lucid | * |
Python3.1 | Ubuntu | maverick | * |
Python3.1 | Ubuntu | natty | * |
Python3.1 | Ubuntu | upstream | * |
Python3.2 | Ubuntu | natty | * |
Python3.2 | Ubuntu | oneiric | * |
Python3.2 | Ubuntu | precise | * |
Python3.2 | Ubuntu | quantal | * |
Python3.2 | Ubuntu | upstream | * |
Python3.3 | Ubuntu | upstream | * |