PYSEC-2014-115
Withdrawn 2024-11-22. This finding no longer applies and is kept for reference. It is not used when checking packages.
Details
The urlopen function in pym/portage/util/_urlopen.py in Gentoo Portage 2.1.12, when using HTTPS, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and modify binary package lists via a crafted certificate.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/portage
Introduced in:
0No fixed version published yet for portage (pip). Pin to a known-safe version or switch to an alternative.
References
- http://openwall.com/lists/oss-security/2013/05/15/5[EVIDENCE]
- http://www.securityfocus.com/bid/59878[WEB]
- http://openwall.com/lists/oss-security/2013/05/16/3[WEB]
- https://bugs.gentoo.org/show_bug.cgi?id=469888[FIX]
- https://security.gentoo.org/glsa/201507-16[ADVISORY]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84315[WEB]
- https://github.com/advisories/GHSA-8823-xphr-qw9v[ADVISORY]