The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that references an untrusted module in Digest/.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libmodule-signature-perl | Jul 30, 2024 | Aug 19, 2013 |
| Gentoo Linux | — | Upgrade dev-perl/Module-Signature. | Oct 30, 2017 | Aug 19, 2013 |
| Suse | — | Upgrade perl-Module-Signature | Dec 12, 2013 | Aug 19, 2013 |
| Ubuntu | — | Upgrade libmodule-signature-perl | Nov 8, 2024 | Aug 19, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub