CVE-2023-35845
- EPSS 0.02%
- Veröffentlicht 11.09.2023 08:15:07
- Zuletzt bearbeitet 21.11.2024 08:08:48
Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying the cacert.pem file used by the installed pip program. This occurs because many files are installed as world-writable on Linux, ignoring umask, even when...
CVE-2021-42969
- EPSS 5.3%
- Veröffentlicht 13.05.2022 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:28:20
Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the user opens the terminal or activates Anaconda, the command will be exec...
CVE-2022-26526
- EPSS 0.14%
- Veröffentlicht 17.03.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:54:06
Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writable directory under %PROGRAMDATA% and place that directory into the system PATH environment variable. Thus, for example, local user...