// For flags

CVE-2011-4944

python: distutils creates ~/.pypirc insecurely

Severity Score

1.9
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

Python v2.6 a través de 3.2 crea ~/.pypirc con permisos de lectura en todo el mundo antes de cambiar los datos que se han escrito, introduce una condición de carrera que permite a usuarios locales obtener un nombre de usuario y contraseña mediante la lectura de este archivo.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
Attack Vector
Local
Attack Complexity
High
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-12-23 CVE Reserved
  • 2012-06-18 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.6.1
Search vendor "Python" for product "Python" and version "2.6.1"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.6.2
Search vendor "Python" for product "Python" and version "2.6.2"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.6.3
Search vendor "Python" for product "Python" and version "2.6.3"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.6.4
Search vendor "Python" for product "Python" and version "2.6.4"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.6.5
Search vendor "Python" for product "Python" and version "2.6.5"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.6.6
Search vendor "Python" for product "Python" and version "2.6.6"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.6.7
Search vendor "Python" for product "Python" and version "2.6.7"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.6.8
Search vendor "Python" for product "Python" and version "2.6.8"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.6.2150
Search vendor "Python" for product "Python" and version "2.6.2150"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.6.6150
Search vendor "Python" for product "Python" and version "2.6.6150"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.7.1
Search vendor "Python" for product "Python" and version "2.7.1"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.7.1
Search vendor "Python" for product "Python" and version "2.7.1"
rc1
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.7.2
Search vendor "Python" for product "Python" and version "2.7.2"
rc1
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.7.3
Search vendor "Python" for product "Python" and version "2.7.3"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.7.1150
Search vendor "Python" for product "Python" and version "2.7.1150"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.7.1150
Search vendor "Python" for product "Python" and version "2.7.1150"
x64
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
2.7.2150
Search vendor "Python" for product "Python" and version "2.7.2150"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
3.0
Search vendor "Python" for product "Python" and version "3.0"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
3.0.1
Search vendor "Python" for product "Python" and version "3.0.1"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
3.1
Search vendor "Python" for product "Python" and version "3.1"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
3.1.1
Search vendor "Python" for product "Python" and version "3.1.1"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
3.1.2
Search vendor "Python" for product "Python" and version "3.1.2"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
3.1.3
Search vendor "Python" for product "Python" and version "3.1.3"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
3.1.4
Search vendor "Python" for product "Python" and version "3.1.4"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
3.1.5
Search vendor "Python" for product "Python" and version "3.1.5"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
3.1.2150
Search vendor "Python" for product "Python" and version "3.1.2150"
x64
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
3.2
Search vendor "Python" for product "Python" and version "3.2"
-
Affected
Python
Search vendor "Python"
Python
Search vendor "Python" for product "Python"
3.2
Search vendor "Python" for product "Python" and version "3.2"
alpha
Affected