CVE-2020-16156
published 2022-10-19CVE-2020-16156: Title: Perl vulnerability Summary: Perl could be made to by pass signature verification. It was discovered that Perl incorrectly handled certain signature…
high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.79%
52.5th percentile
Title: Perl vulnerability
Summary: Perl could be made to by pass signature verification.
It was discovered that Perl incorrectly handled certain signature verification.
An remote attacker could possibly use this issue to bypass signature verification.
Instructions: In general, a standard system update will make all the necessary changes.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | perl | < perl 5.36.0-4 (bookworm) | perl 5.36.0-4 (bookworm) |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_debian7.8HIGH
vendor_oracle7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Perl DBI) — CVE-2020-16156
vendor_oracle·2023-01-15·CVSS 7.8
CVE-2020-16156 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Core (Perl DBI) — CVE-2020-16156
Oracle Oracle Communications Applications Risk Matrix: Core (Perl DBI) vulnerability
CVE: CVE-2020-16156
CVSS: 7.8
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2023 (JAN 2023)
Ubuntu
Perl vulnerability
vendor_ubuntu·2022-11-28
CVE-2020-16156 Perl vulnerability
Title: Perl vulnerability
Summary: Perl could be made to by pass signature verification.
USN-5689-1 fixed a vulnerability in Perl.
This update provides the corresponding update for Ubuntu 22.10.
Original advisory details:
It was discovered that Perl incorrectly handled certain signature verification.
An remote attacker could possibly use this issue to bypass signature verification.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Perl vulnerability
vendor_ubuntu·2022-10-19
CVE-2020-16156 Perl vulnerability
Title: Perl vulnerability
Summary: Perl could be made to by pass signature verification.
It was discovered that Perl incorrectly handled certain signature verification.
An remote attacker could possibly use this issue to bypass signature verification.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
perl-CPAN: Bypass of verification of signatures in CHECKSUMS files
vendor_redhat·2021-11-23·CVSS 7.8
CVE-2020-16156 [HIGH] CWE-347 perl-CPAN: Bypass of verification of signatures in CHECKSUMS files
perl-CPAN: Bypass of verification of signatures in CHECKSUMS files
CPAN 2.28 allows Signature Verification Bypass.
A flaw was found in the way the perl-CPAN performed verification of package signatures stored in CHECKSUMS files. A malicious or compromised CPAN server used by a user, or a man-in-the-middle attacker, could use this flaw to bypass signature verification.
Statement: This vulnerability is assigned a Moderate Severity rating primarily because of the multistep nature of the attack and the efficacy of environmental security controls. The underlying issue is a serious software flaw, designated as CWE 347: Improper Verification of Cryptographic Signature, which means the system fails to correctly verify the digital authenticity of installation packages, potentially allowing an at
Debian
CVE-2020-16156: perl - CPAN 2.28 allows Signature Verification Bypass.
vendor_debian·2020·CVSS 7.8
CVE-2020-16156 [HIGH] CVE-2020-16156: perl - CPAN 2.28 allows Signature Verification Bypass.
CPAN 2.28 allows Signature Verification Bypass.
Scope: local
bookworm: resolved (fixed in 5.36.0-4)
bullseye: resolved (fixed in 5.32.1-4+deb11u4)
forky: resolved (fixed in 5.36.0-4)
sid: resolved (fixed in 5.36.0-4)
trixie: resolved (fixed in 5.36.0-4)
No detection rules found.
No writeups or analysis indexed.
2022-10-19
Published