CVE-2013-5123
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2013-5123?
CVE-2013-5123 is a vulnerability that affects the mirroring support (-M, --use-mirrors) in Python Pip before version 1.5.
How does CVE-2013-5123 work?
CVE-2013-5123 relies on insecure DNS querying and authenticity checks, allowing attackers to perform man-in-the-middle attacks.
Which software is affected by CVE-2013-5123?
The software affected by CVE-2013-5123 includes Python Pip before version 1.5, Pypa Pip version up to 1.5, Virtualenv Virtualenv version 12.0.7, Fedoraproject Fedora versions 20 and 21, IBM Robotic Process Automation as a Service versions 1.0 and 2.0, Redhat Software Collections, and Debian Debian Linux versions 8.0, 9.0, and 10.0.
What is the severity of CVE-2013-5123?
The severity of CVE-2013-5123 is medium with a score of 5.9.
How can CVE-2013-5123 be fixed?
To fix CVE-2013-5123, update Python Pip to version 1.5 or later, or apply the recommended patches for the affected software.