CVE-2015-3409
published 2015-05-19CVE-2015-3409: Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working…
PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.41%
33.6th percentile
Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff module.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libmodule-signature-perl | < libmodule-signature-perl 0.78-1 (bookworm) | libmodule-signature-perl 0.78-1 (bookworm) |
| module-signature_project | module-signature | <= 0.74 | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-43mv-gcv3-rmpw: Untrusted search path vulnerability in Module::Signature before 0
ghsa_unreviewed·2022-05-17
CVE-2015-3409 [HIGH] GHSA-43mv-gcv3-rmpw: Untrusted search path vulnerability in Module::Signature before 0
Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff module.
OSV
CVE-2015-3409: Untrusted search path vulnerability in Module::Signature before 0
osv·2015-05-19·CVSS 7.2
CVE-2015-3409 [HIGH] CVE-2015-3409: Untrusted search path vulnerability in Module::Signature before 0
Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff module.
OSV
libmodule-signature-perl vulnerabilities
osv·2015-05-12·CVSS 7.5
CVE-2015-3406 [HIGH] libmodule-signature-perl vulnerabilities
libmodule-signature-perl vulnerabilities
John Lightsey discovered that Module::Signature incorrectly handled PGP
signature boundaries. A remote attacker could use this issue to trick
Module::Signature into parsing the unsigned portion of the SIGNATURE file
as the signed portion. (CVE-2015-3406)
John Lightsey discovered that Module::Signature incorrectly handled files
that were not listed in the SIGNATURE file. A remote attacker could use
this flaw to execute arbitrary code when tests were run. (CVE-2015-3407)
John Lightsey discovered that Module::Signature incorrectly handled
embedded shell commands in the SIGNATURE file. A remote attacker could use
this issue to execute arbitrary code during signature verification.
(CVE-2015-3408)
John Lightsey discovered that Module::Signature incorr
Ubuntu
Module::Signature vulnerabilities
vendor_ubuntu·2015-05-12·CVSS 7.5
CVE-2015-3406 [HIGH] Module::Signature vulnerabilities
Title: Module::Signature vulnerabilities
Summary: Several security issues were fixed in Module::Signature.
John Lightsey discovered that Module::Signature incorrectly handled PGP
signature boundaries. A remote attacker could use this issue to trick
Module::Signature into parsing the unsigned portion of the SIGNATURE file
as the signed portion. (CVE-2015-3406)
John Lightsey discovered that Module::Signature incorrectly handled files
that were not listed in the SIGNATURE file. A remote attacker could use
this flaw to execute arbitrary code when tests were run. (CVE-2015-3407)
John Lightsey discovered that Module::Signature incorrectly handled
embedded shell commands in the SIGNATURE file. A remote attacker could use
this issue to execute arbitrary code during signature verification.
(CVE
Red Hat
perl-Module-Signature: arbitrary modules loading in some circumstances
vendor_redhat·2015-04-05·CVSS 7.2
CVE-2015-3409 [HIGH] CWE-20 perl-Module-Signature: arbitrary modules loading in some circumstances
perl-Module-Signature: arbitrary modules loading in some circumstances
Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff module.
Package: perl-Module-Signature (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2015-3409: libmodule-signature-perl - Untrusted search path vulnerability in Module::Signature before 0.75 allows loca...
vendor_debian·2015·CVSS 7.2
CVE-2015-3409 [HIGH] CVE-2015-3409: libmodule-signature-perl - Untrusted search path vulnerability in Module::Signature before 0.75 allows loca...
Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff module.
Scope: local
bookworm: resolved (fixed in 0.78-1)
bullseye: resolved (fixed in 0.78-1)
forky: resolved (fixed in 0.78-1)
sid: resolved (fixed in 0.78-1)
trixie: resolved (fixed in 0.78-1)
No detection rules found.
No public exploits indexed.
http://ubuntu.com/usn/usn-2607-1http://www.debian.org/security/2015/dsa-3261http://www.openwall.com/lists/oss-security/2015/04/07/1http://www.openwall.com/lists/oss-security/2015/04/23/17http://www.securityfocus.com/bid/73937https://github.com/audreyt/module-signature/commit/c41e8885b862b9fce2719449bc9336f0bea658efhttps://metacpan.org/changes/distribution/Module-Signaturehttp://ubuntu.com/usn/usn-2607-1http://www.debian.org/security/2015/dsa-3261http://www.openwall.com/lists/oss-security/2015/04/07/1http://www.openwall.com/lists/oss-security/2015/04/23/17http://www.securityfocus.com/bid/73937https://github.com/audreyt/module-signature/commit/c41e8885b862b9fce2719449bc9336f0bea658efhttps://metacpan.org/changes/distribution/Module-Signature
2015-05-19
Published