CVE-2015-3406
published 2019-11-29CVE-2015-3406: The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
2.29%
81.3th percentile
The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libmodule-signature-perl | < libmodule-signature-perl 0.78-1 (bookworm) | libmodule-signature-perl 0.78-1 (bookworm) |
| module-signature_project | module-signature | < 0.74 | 0.74 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2jr6-2g4g-4jhj: The PGP signature parsing in Module::Signature before 0
ghsa_unreviewed·2022-05-24
CVE-2015-3406 [MEDIUM] GHSA-2jr6-2g4g-4jhj: The PGP signature parsing in Module::Signature before 0
The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.
OSV
CVE-2015-3406: The PGP signature parsing in Module::Signature before 0
osv·2019-11-29·CVSS 7.5
CVE-2015-3406 [HIGH] CVE-2015-3406: The PGP signature parsing in Module::Signature before 0
The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.
OSV
libmodule-signature-perl vulnerabilities
osv·2015-05-12·CVSS 7.5
CVE-2015-3406 [HIGH] libmodule-signature-perl vulnerabilities
libmodule-signature-perl vulnerabilities
John Lightsey discovered that Module::Signature incorrectly handled PGP
signature boundaries. A remote attacker could use this issue to trick
Module::Signature into parsing the unsigned portion of the SIGNATURE file
as the signed portion. (CVE-2015-3406)
John Lightsey discovered that Module::Signature incorrectly handled files
that were not listed in the SIGNATURE file. A remote attacker could use
this flaw to execute arbitrary code when tests were run. (CVE-2015-3407)
John Lightsey discovered that Module::Signature incorrectly handled
embedded shell commands in the SIGNATURE file. A remote attacker could use
this issue to execute arbitrary code during signature verification.
(CVE-2015-3408)
John Lightsey discovered that Module::Signature incorr
Ubuntu
Module::Signature vulnerabilities
vendor_ubuntu·2015-05-12·CVSS 7.5
CVE-2015-3406 [HIGH] Module::Signature vulnerabilities
Title: Module::Signature vulnerabilities
Summary: Several security issues were fixed in Module::Signature.
John Lightsey discovered that Module::Signature incorrectly handled PGP
signature boundaries. A remote attacker could use this issue to trick
Module::Signature into parsing the unsigned portion of the SIGNATURE file
as the signed portion. (CVE-2015-3406)
John Lightsey discovered that Module::Signature incorrectly handled files
that were not listed in the SIGNATURE file. A remote attacker could use
this flaw to execute arbitrary code when tests were run. (CVE-2015-3407)
John Lightsey discovered that Module::Signature incorrectly handled
embedded shell commands in the SIGNATURE file. A remote attacker could use
this issue to execute arbitrary code during signature verification.
(CVE
Red Hat
perl-Module-Signature: unsigned files interpreted as signed in some circumstances
vendor_redhat·2015-04-05·CVSS 7.5
CVE-2015-3406 [HIGH] CWE-347 perl-Module-Signature: unsigned files interpreted as signed in some circumstances
perl-Module-Signature: unsigned files interpreted as signed in some circumstances
The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.
Package: perl-Module-Signature (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2015-3406: libmodule-signature-perl - The PGP signature parsing in Module::Signature before 0.74 allows remote attacke...
vendor_debian·2015·CVSS 7.5
CVE-2015-3406 [HIGH] CVE-2015-3406: libmodule-signature-perl - The PGP signature parsing in Module::Signature before 0.74 allows remote attacke...
The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.78-1)
bullseye: resolved (fixed in 0.78-1)
forky: resolved (fixed in 0.78-1)
sid: resolved (fixed in 0.78-1)
trixie: resolved (fixed in 0.78-1)
No detection rules found.
No public exploits indexed.
http://ubuntu.com/usn/usn-2607-1http://www.openwall.com/lists/oss-security/2015/04/07/1http://www.openwall.com/lists/oss-security/2015/04/23/17https://github.com/audreyt/module-signature/commit/8a9164596fa5952d4fbcde5aa1c7d1c7bc85372fhttps://metacpan.org/changes/distribution/Module-Signaturehttp://ubuntu.com/usn/usn-2607-1http://www.openwall.com/lists/oss-security/2015/04/07/1http://www.openwall.com/lists/oss-security/2015/04/23/17https://github.com/audreyt/module-signature/commit/8a9164596fa5952d4fbcde5aa1c7d1c7bc85372fhttps://metacpan.org/changes/distribution/Module-Signature
2019-11-29
Published