| |
Vulnerability CVE-2023-35845
Published: 2023-09-11
| Description: |
Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying the cacert.pem file used by the installed pip program. This occurs because many files are installed as world-writable on Linux, ignoring umask, even when these files are installed as root. Miniconda is also affected. |
References: |
https://uponfurtherinvestigation.blogspot.com/2023/06/cve-2023-35845-anaconda3-creates.html
|
|
|
closedb();
?>
Copyright 2026, cxsecurity.com
|
|
|