VDB
Sign up
—

PYSEC-2013-10

Quick fix

PYSEC-2013-10 — pyshop: upgrade to the fixed version with the command below.

pip install --upgrade 'pyshop>=ffadb0bcdef1e385884571670210cfd6ba351784'

Details

pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a download operation.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pyshop
Introduced in: 0Fixed in: ffadb0bcdef1e385884571670210cfd6ba351784
Fixpip install --upgrade 'pyshop>=ffadb0bcdef1e385884571670210cfd6ba351784'

References