PT-2019-13316 · Python · Python
Published
2019-07-08
·
Updated
2024-08-05
·
CVE-2019-13404
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Python versions prior to 2.7.17
Python versions 3.x prior to 3.5
Description
The MSI installer for Python on Windows defaults to the C:Python27 directory, making it easier for local users to deploy Trojan horse code. The vendor's position is that it is the user's responsibility to ensure C:Python27 access control or choose a different directory, due to backwards compatibility requirements.
Recommendations
For Python versions prior to 2.7.17, consider choosing a different directory during installation to minimize the risk of exploitation.
For Python versions 3.x prior to 3.5, consider choosing a different directory during installation to minimize the risk of exploitation.
As a temporary workaround, ensure proper access control for the C:Python27 directory to prevent unauthorized access.
Exploit
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Python