CVE-2015-3407
published 2015-05-19CVE-2015-3407: Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.
PriorityP429medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
2.36%
81.9th percentile
Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libmodule-signature-perl | < libmodule-signature-perl 0.78-1 (bookworm) | libmodule-signature-perl 0.78-1 (bookworm) |
| module-signature_project | module-signature | <= 0.73 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2qpg-g63h-ghqr: Module::Signature before 0
ghsa_unreviewed·2022-05-17
CVE-2015-3407 [MEDIUM] CWE-284 GHSA-2qpg-g63h-ghqr: Module::Signature before 0
Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.
OSV
CVE-2015-3407: Module::Signature before 0
osv·2015-05-19·CVSS 5.0
CVE-2015-3407 [MEDIUM] CVE-2015-3407: Module::Signature before 0
Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.
OSV
libmodule-signature-perl vulnerabilities
osv·2015-05-12·CVSS 7.5
CVE-2015-3406 [HIGH] libmodule-signature-perl vulnerabilities
libmodule-signature-perl vulnerabilities
John Lightsey discovered that Module::Signature incorrectly handled PGP
signature boundaries. A remote attacker could use this issue to trick
Module::Signature into parsing the unsigned portion of the SIGNATURE file
as the signed portion. (CVE-2015-3406)
John Lightsey discovered that Module::Signature incorrectly handled files
that were not listed in the SIGNATURE file. A remote attacker could use
this flaw to execute arbitrary code when tests were run. (CVE-2015-3407)
John Lightsey discovered that Module::Signature incorrectly handled
embedded shell commands in the SIGNATURE file. A remote attacker could use
this issue to execute arbitrary code during signature verification.
(CVE-2015-3408)
John Lightsey discovered that Module::Signature incorr
Ubuntu
Module::Signature vulnerabilities
vendor_ubuntu·2015-05-12·CVSS 7.5
CVE-2015-3406 [HIGH] Module::Signature vulnerabilities
Title: Module::Signature vulnerabilities
Summary: Several security issues were fixed in Module::Signature.
John Lightsey discovered that Module::Signature incorrectly handled PGP
signature boundaries. A remote attacker could use this issue to trick
Module::Signature into parsing the unsigned portion of the SIGNATURE file
as the signed portion. (CVE-2015-3406)
John Lightsey discovered that Module::Signature incorrectly handled files
that were not listed in the SIGNATURE file. A remote attacker could use
this flaw to execute arbitrary code when tests were run. (CVE-2015-3407)
John Lightsey discovered that Module::Signature incorrectly handled
embedded shell commands in the SIGNATURE file. A remote attacker could use
this issue to execute arbitrary code during signature verification.
(CVE
Red Hat
perl-Module-Signature: arbitrary code execution during test phase
vendor_redhat·2015-04-05·CVSS 5.0
CVE-2015-3407 [MEDIUM] CWE-20 perl-Module-Signature: arbitrary code execution during test phase
perl-Module-Signature: arbitrary code execution during test phase
Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.
Package: perl-Module-Signature (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2015-3407: libmodule-signature-perl - Module::Signature before 0.74 allows remote attackers to bypass signature verifi...
vendor_debian·2015·CVSS 5.0
CVE-2015-3407 [MEDIUM] CVE-2015-3407: libmodule-signature-perl - Module::Signature before 0.74 allows remote attackers to bypass signature verifi...
Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.
Scope: local
bookworm: resolved (fixed in 0.78-1)
bullseye: resolved (fixed in 0.78-1)
forky: resolved (fixed in 0.78-1)
sid: resolved (fixed in 0.78-1)
trixie: resolved (fixed in 0.78-1)
No detection rules found.
No public exploits indexed.
http://ubuntu.com/usn/usn-2607-1http://www.debian.org/security/2015/dsa-3261http://www.openwall.com/lists/oss-security/2015/04/07/1http://www.openwall.com/lists/oss-security/2015/04/23/17https://github.com/audreyt/module-signature/commit/8a9164596fa5952d4fbcde5aa1c7d1c7bc85372fhttps://metacpan.org/changes/distribution/Module-Signaturehttp://ubuntu.com/usn/usn-2607-1http://www.debian.org/security/2015/dsa-3261http://www.openwall.com/lists/oss-security/2015/04/07/1http://www.openwall.com/lists/oss-security/2015/04/23/17https://github.com/audreyt/module-signature/commit/8a9164596fa5952d4fbcde5aa1c7d1c7bc85372fhttps://metacpan.org/changes/distribution/Module-Signature
2015-05-19
Published