CVE-2020-1615513.12.2021, 18:15The CPAN::Checksums package 2.12 for Perl does not uniquely define signed data.EnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST6.5 MEDIUMNETWORKLOWLOWCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NmitreCNA------CVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 42%Debian ReleasesDebian ProductCodenamelibcpan-checksums-perlbullseyeno-dsabusterno-dsastretchno-dsabookworm2.14-1fixedsid2.14-2fixedtrixie2.14-2fixedUbuntu ReleasesUbuntu ProductCodenamelibcpan-checksums-perlnobleneededmanticignoredlunarignoredkineticignoredjammyneededimpishignoredhirsuteignoredfocalneededbionicneededxenialneeds-triagetrustyignoredKnown Exploits!https://blog.hackeriet.no/cpan-signature-verification-vulnerabilities/https://blog.hackeriet.no/cpan-signature-verification-vulnerabilities/Referenceshttps://blog.hackeriet.no/cpan-signature-verification-vulnerabilities/https://metacpan.org/pod/CPAN::Checksumshttps://blog.hackeriet.no/cpan-signature-verification-vulnerabilities/https://metacpan.org/pod/CPAN::Checksums