CVE-2013-2145
published 2013-08-19CVE-2013-2145: The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary…
PriorityP425medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.56%
42.7th percentile
The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that references an untrusted module in Digest/.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libmodule-signature-perl | < libmodule-signature-perl 0.73-1 (bookworm) | libmodule-signature-perl 0.73-1 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| perlmonks | module | <= 0.72 | — |
| perlmonks | module | — | — |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Module::Signature perl module vulnerability
vendor_ubuntu·2013-07-03
CVE-2013-2145 Module::Signature perl module vulnerability
Title: Module::Signature perl module vulnerability
Summary: Module::Signature could be made to run programs if it verified a signature.
Florian Weimer discovered that the Module::Signature perl module
incorrectly loaded unknown ciphers from relative directories. An attacker
could possibly use this flaw to execute arbitrary code when a signature is
verified.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2013-2145: libmodule-signature-perl - The cpansign verify functionality in the Module::Signature module before 0.72 fo...
vendor_debian·2013·CVSS 4.4
CVE-2013-2145 [MEDIUM] CVE-2013-2145: libmodule-signature-perl - The cpansign verify functionality in the Module::Signature module before 0.72 fo...
The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that references an untrusted module in Digest/.
Scope: local
bookworm: resolved (fixed in 0.73-1)
bullseye: resolved (fixed in 0.73-1)
forky: resolved (fixed in 0.73-1)
sid: resolved (fixed in 0.73-1)
trixie: resolved (fixed in 0.73-1)
GHSA
GHSA-99g4-3v63-xpqx: The cpansign verify functionality in the Module::Signature module before 0
ghsa_unreviewed·2022-05-14
CVE-2013-2145 [MEDIUM] CWE-20 GHSA-99g4-3v63-xpqx: The cpansign verify functionality in the Module::Signature module before 0
The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that references an untrusted module in Digest/.
OSV
CVE-2013-2145: The cpansign verify functionality in the Module::Signature module before 0
osv·2013-08-19·CVSS 4.4
CVE-2013-2145 [MEDIUM] CVE-2013-2145: The cpansign verify functionality in the Module::Signature module before 0
The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that references an untrusted module in Digest/.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2145 perl-Module-Signature: arbitrary code execution when verifying SIGNATURE [epel-all]
bugzilla·2013-06-05·CVSS 4.4
CVE-2013-2145 [MEDIUM] CVE-2013-2145 perl-Module-Signature: arbitrary code execution when verifying SIGNATURE [epel-all]
CVE-2013-2145 perl-Module-Signature: arbitrary code execution when verifying SIGNATURE [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Pl
Bugzilla
CVE-2013-2145 perl-Module-Signature: arbitrary code execution when verifying SIGNATURE
bugzilla·2013-06-05·CVSS 4.4
CVE-2013-2145 [MEDIUM] CVE-2013-2145 perl-Module-Signature: arbitrary code execution when verifying SIGNATURE
CVE-2013-2145 perl-Module-Signature: arbitrary code execution when verifying SIGNATURE
The perl Module::Signature module adds signing capabilities to CPAN modules. The 'cpansign verify' command will automatically download keys and use them to check the signature of CPAN packages via the SIGNATURE file.
The format of the SIGNATURE file includes the cipher to use to match the provided hash; for instance:
SHA1 955ba924e9cd1bafccb4d6d7bd3be25c3ce8bf75 README
If an attacker were to replace this (SHA1) with a special unknown cipher (e.g. 'Special') and were to include in the distribution a 'Digest/Special.pm', the code in this perl module would be executed when 'cpansign -verify' is run. This will execute arbitrary code with the privileges of the user running cpansign.
Because cpansign will
Bugzilla
CVE-2013-2145 perl-Module-Signature: arbitrary code execution when verifying SIGNATURE [fedora-all]
bugzilla·2013-06-05·CVSS 4.4
CVE-2013-2145 [MEDIUM] CVE-2013-2145 perl-Module-Signature: arbitrary code execution when verifying SIGNATURE [fedora-all]
CVE-2013-2145 perl-Module-Signature: arbitrary code execution when verifying SIGNATURE [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Pleas
http://lists.opensuse.org/opensuse-updates/2013-07/msg00039.htmlhttp://lists.opensuse.org/opensuse-updates/2013-07/msg00043.htmlhttp://www.openwall.com/lists/oss-security/2013/06/05/16http://www.securityfocus.com/bid/60352http://www.ubuntu.com/usn/USN-1896-1https://bugzilla.redhat.com/show_bug.cgi?id=971096https://github.com/audreyt/module-signature/commit/575f7bd6ba4cc7c92f841e8758f88a131674ebf2https://github.com/audreyt/module-signature/commit/cbd06b392a73c63159dc5c20ff5b3c8fc88c4896http://lists.opensuse.org/opensuse-updates/2013-07/msg00039.htmlhttp://lists.opensuse.org/opensuse-updates/2013-07/msg00043.htmlhttp://www.openwall.com/lists/oss-security/2013/06/05/16http://www.securityfocus.com/bid/60352http://www.ubuntu.com/usn/USN-1896-1https://bugzilla.redhat.com/show_bug.cgi?id=971096https://github.com/audreyt/module-signature/commit/575f7bd6ba4cc7c92f841e8758f88a131674ebf2https://github.com/audreyt/module-signature/commit/cbd06b392a73c63159dc5c20ff5b3c8fc88c4896
2013-08-19
Published