Vulnerability Name:

CVE-2013-5123 (CCN-106420)

Assigned:2013-08-15
Published:2015-07-31
Updated:2019-11-12
Summary:The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
CVSS v3 Severity:5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-287
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2013-5123

Source: MISC
Type: Mailing List, Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155248.html

Source: MISC
Type: Mailing List, Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/155291.html

Source: CCN
Type: IBM Security Bulletin T1022786
Vulnerabilities in Python affect PowerKVM (CVE-2013-5123, CVE-2014-8991)

Source: MISC
Type: Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2013/08/21/17

Source: MISC
Type: Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2013/08/21/18

Source: MISC
Type: Broken Link, Third Party Advisory, VDB Entry
http://www.securityfocus.com/bid/77520

Source: CCN
Type: Red Hat Bugzilla – Bug 1066692
(CVE-2013-5123) CVE-2013-5123 python-pip: insecure software download with mirroring support

Source: MISC
Type: Issue Tracking, Patch, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-5123

Source: MISC
Type: Issue Tracking, Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-5123

Source: XF
Type: UNKNOWN
python-pip-cve20135123-sec-bypass(106420)

Source: CCN
Type: pip GIT Repository
Remove direct support for PEP381 Mirrors #1098

Source: MISC
Type: Third Party Advisory
https://security-tracker.debian.org/tracker/CVE-2013-5123

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2013-5123

Vulnerable Configuration:Configuration 1:
  • cpe:/a:pypa:pip:*:*:*:*:*:*:*:* (Version < 1.5)
  • OR cpe:/a:virtualenv:virtualenv:12.0.7:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:fedoraproject:fedora:20:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:21:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:redhat:openshift:1.0:*:*:*:enterprise:*:*:*
  • OR cpe:/a:redhat:openshift:2.0:*:*:*:enterprise:*:*:*
  • OR cpe:/a:redhat:software_collections:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:python:pip:1.5.6:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:powerkvm:2.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20135123
    V
    CVE-2013-5123
    2022-09-02
    oval:org.opensuse.security:def:549
    P
    Security update for 389-ds (Important)
    2022-07-06
    oval:org.opensuse.security:def:254
    P
    p7zip-16.02-14.2.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:874
    P
    Security update for python39 (Moderate)
    2022-05-02
    oval:org.opensuse.security:def:962
    P
    Security update for vim (Important)
    2022-03-04
    oval:org.opensuse.security:def:113227
    P
    python2-pip-20.0.2-2.6 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:113281
    P
    python36-pip-20.2.4-1.8 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:113215
    P
    python-pip-8.1.2-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:69966
    P
    Security update for xen (Moderate)
    2021-12-09
    oval:org.opensuse.security:def:64604
    P
    Security update for busybox (Important)
    2021-10-27
    oval:org.opensuse.security:def:106645
    P
    python2-pip-20.0.2-2.6 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:106693
    P
    python36-pip-20.2.4-1.8 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:106633
    P
    python-pip-8.1.2-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:1483
    P
    Security update for gd (Moderate)
    2021-09-27
    oval:org.opensuse.security:def:71149
    P
    bind-devel-9.11.2-12.8.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61638
    P
    python3-pip-10.0.1-1.9 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71278
    P
    liblzo2-2-2.10-2.22 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96758
    P
    python3-pip-10.0.1-1.9 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71379
    P
    python3-pip-10.0.1-1.9 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71391
    P
    rzsz-0.12.21~rc-1.8 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103448
    P
    python3-pip-10.0.1-1.9 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:89793
    P
    python3-pip-10.0.1-1.9 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:67796
    P
    Security update for the Linux Kernel (Live Patch 25 for SLE 15) (Important)
    2021-09-16
    oval:org.opensuse.security:def:68038
    P
    Security update for the Linux Kernel (Live Patch 23 for SLE 15 SP1) (Important)
    2021-08-17
    oval:org.opensuse.security:def:47206
    P
    apache2-mod_nss-1.0.14-18.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48069
    P
    libSDL-1_2-0-1.2.15-15.11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47476
    P
    procmail-3.22-267.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47812
    P
    libxcb-dri2-0-1.10-4.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47085
    P
    libtcnative-1-0-1.1.32-9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48003
    P
    evince-3.20.2-6.27.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47985
    P
    curl-7.60.0-9.8 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47328
    P
    libXxf86vm1-1.1.3-3.53 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47619
    P
    giflib-progs-5.0.5-12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47071
    P
    libraptor2-0-2.0.10-3.63 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47932
    P
    yast2-users-3.2.17-1.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47771
    P
    libpulse-mainloop-glib0-32bit-5.0-4.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47236
    P
    cyrus-sasl-2.1.26-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47498
    P
    sane-backends-1.0.24-3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48298
    P
    rsyslog-8.24.0-3.28.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47070
    P
    libqt4-32bit-4.8.6-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47901
    P
    tar-1.27.1-15.3.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47623
    P
    gnome-keyring-3.20.0-28.3.18 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47104
    P
    mailx-12.5-28.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47484
    P
    python-pywbem-0.7.0-4.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48227
    P
    libxml2-2-2.9.4-46.20.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47836
    P
    openvpn-2.3.8-16.20.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48184
    P
    libqt4-32bit-4.8.7-8.8.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47531
    P
    xf86-video-intel-2.99.917.770_gcb6ba2da-1.23 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46911
    P
    cpp48-4.8.5-30.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47483
    P
    python-pyOpenSSL-16.0.0-2.3.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48196
    P
    libspice-client-glib-2_0-8-0.33-3.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47774
    P
    libqpdf18-7.1.1-3.3.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48036
    P
    guestfs-data-1.32.4-21.3.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47399
    P
    libpulse-mainloop-glib0-32bit-5.0-4.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48131
    P
    libjavascriptcoregtk-3_0-0-2.4.11-23.20 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47690
    P
    libXxf86vm1-1.1.3-3.53 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47944
    P
    alsa-1.0.27.2-15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:71036
    P
    libudisks2-0-2.6.5-1.47 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46776
    P
    libtag1-1.9.1-1.265 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48609
    P
    python-pywbem-0.7.0-4.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48695
    P
    libssh4-0.6.3-1.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71084
    P
    python2-pip-10.0.1-1.9 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46775
    P
    libssh2-1-1.4.3-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48544
    P
    libqt4-4.8.6-7.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48482
    P
    libarchive13-3.1.2-22.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48641
    P
    vino-3.20.2-5.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48398
    P
    cyrus-sasl-2.1.26-7.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48936
    P
    libofx-0.9.9-3.7.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48711
    P
    bash-lang-4.2-75.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46790
    P
    logrotate-3.8.7-3.21 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48640
    P
    update-alternatives-1.18.4-14.216 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:69861
    P
    Security update for libX11 (Important)
    2021-06-08
    oval:org.opensuse.security:def:61343
    P
    python2-pip-10.0.1-1.9 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64691
    P
    Security update for fribidi (Important)
    2021-05-19
    oval:org.opensuse.security:def:100643
    P
    (Important)
    2021-02-01
    oval:org.opensuse.security:def:64449
    P
    Security update for clamav (Moderate)
    2020-12-14
    oval:org.opensuse.security:def:67938
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 15 SP1) (Important)
    2020-12-07
    oval:org.opensuse.security:def:93930
    P
    python3-pip-10.0.1-1.9 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:48990
    P
    gnome-online-accounts-3.20.8-10.4.50 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61963
    P
    python3-pip-10.0.1-1.9 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71704
    P
    python3-pip-10.0.1-1.9 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107309
    P
    python3-pip-10.0.1-1.9 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116867
    P
    python3-pip-10.0.1-1.9 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:66518
    P
    libpython2_7-1_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49870
    P
    python2-numpy-gnu-hpc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67696
    P
    libminizip1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64362
    P
    libopus0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73183
    P
    libmpg123-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49315
    P
    python3-pip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66610
    P
    python3-pip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73301
    P
    python3-pip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49924
    P
    python2-pip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49261
    P
    libxcb-composite0 on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.xenial:def:201351230000000
    V
    CVE-2013-5123 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-11-05
    oval:com.ubuntu.artful:def:20135123000
    V
    CVE-2013-5123 on Ubuntu 17.10 (artful) - medium.
    2013-08-22
    oval:com.ubuntu.xenial:def:20135123000
    V
    CVE-2013-5123 on Ubuntu 16.04 LTS (xenial) - medium.
    2013-08-22
    oval:com.ubuntu.bionic:def:20135123000
    V
    CVE-2013-5123 on Ubuntu 18.04 LTS (bionic) - medium.
    2013-08-22
    oval:com.ubuntu.precise:def:20135123000
    V
    CVE-2013-5123 on Ubuntu 12.04 LTS (precise) - medium.
    2013-08-22
    oval:com.ubuntu.bionic:def:201351230000000
    V
    CVE-2013-5123 on Ubuntu 18.04 LTS (bionic) - medium.
    2013-08-22
    oval:com.ubuntu.trusty:def:20135123000
    V
    CVE-2013-5123 on Ubuntu 14.04 LTS (trusty) - medium.
    2013-08-22
    BACK
    pypa pip *
    virtualenv virtualenv 12.0.7
    fedoraproject fedora 20
    fedoraproject fedora 21
    redhat openshift 1.0
    redhat openshift 2.0
    redhat software collections -
    debian debian linux 8.0
    debian debian linux 9.0
    debian debian linux 10.0
    python pip 1.5.6
    ibm powerkvm 2.1