| Name | CVE-2013-5123 | 
| Description | The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks. | 
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) | 
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status | 
|---|
| python-pip (PTS) | bullseye | 20.3.4-4+deb11u1 | fixed | 
 | bullseye (security) | 20.3.4-4+deb11u2 | fixed | 
 | bookworm | 23.0.1+dfsg-1 | fixed | 
 | trixie | 25.1.1+dfsg-1 | fixed | 
 | forky | 25.2+dfsg-1 | fixed | 
 | sid | 25.3+dfsg-1 | fixed | 
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs | 
|---|
| python-pip | source | squeeze | (not affected) |  |  |  | 
| python-pip | source | (unstable) | 1.4.1-1 | unimportant |  |  | 
Notes
[squeeze] - python-pip <not-affected> (Support for mirroring introduced in 0.8.1)
This is additional hardening / security feature, not a vulnerabily (despite
the discussion on oss-sec)