Modified
Published: 27 Aug 2012, 23:00
Last modified:07 Aug 2024, 00:23

Vulnerability Summary

Overall Risk (default)
minimal
8/100
CVSS Score
1.9 LOW
v2.0 (nvd)
EPSS Score
0.03% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Aug 2012, 23:00
Published
Vulnerability first disclosed
07 Aug 2024, 00:23
Last Modified
Vulnerability information updated

Description

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

CVSS Metrics

  • v2.0LOWScore: 1.9AV:L/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.03% Percentile: 9%

Techniques & Countermeasures

  • CWE-264Permissions, Privileges, and Access Controls

    Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Affected Systems

  • pythonpython

    2.6.1 | 2.6.2 | 2.6.3 | 2.6.4 | 2.6.5 | 2.6.6 | 2.6.7 | 2.6.8 | 2.6.2150 | 2.6.6150 | 2.7.1 | 2.7.1:rc1 | 2.7.2:rc1 | 2.7.3 | 2.7.1150 | 2.7.2150 | 3.0 | 3.0.1 | 3.1 | 3.1.1 | 3.1.2 | 3.1.3 | 3.1.4 | 3.1.5 | 3.1.2150 | 3.2 | 3.2:alpha

References (20)