CVE-2013-2145
19.08.2013, 23:55
The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that references an untrusted module in Digest/.Enginsight
| Vendor | Product | Version |
|---|---|---|
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 12.10 |
| canonical | ubuntu_linux | 13.04 |
| opensuse | opensuse | 11.4 |
| opensuse | opensuse | 12.2 |
| opensuse | opensuse | 12.3 |
| perlmonks | module\ | 𝑥 ≤ 0.72 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References