CVE-2011-4944
EPSS 0.03%
Description
Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.
How to fix CVE-2011-4944
To remediate CVE-2011-4944, upgrade the affected package to a fixed version below.
- Debian/python2.7—upgrade to 2.7.3~rc2-2 or later
Is CVE-2011-4944 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.7.3~rc2-2