CVE-2013-2145
19.08.2013, 23:55
The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that references an untrusted module in Digest/.Enginsight
Vendor | Product | Version |
---|---|---|
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 12.10 |
canonical | ubuntu_linux | 13.04 |
opensuse | opensuse | 11.4 |
opensuse | opensuse | 12.2 |
opensuse | opensuse | 12.3 |
perlmonks | module\ | 𝑥 ≤ 0.72 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References