Wind River Support Network

HomeDefectsLIN5-16480
Fixed

LIN5-16480 : Security Advisory - python - CVE-2011-4944

Created: Sep 2, 2012    Updated: Dec 19, 2017
Resolved Date: May 19, 2014
Previous ID: LIN2-19186
Found In Version: 5.0
Fix Version: 5.0.1.15
Severity: Low
Applicable for: Wind River Linux 5
Component/s: Userspace

Description

Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a username and password by reading this file.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-4944

Workaround

Unknown

Steps to Reproduce

Unknown

Other Downloads


Live chat
Online