Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian: DSA-3261-1 Critical: libmodule-signature Perl Remote Code Exec

debian
Calendar Grey May 15, 2015
Debian Logo
Several vulnerabilities identified in libmodule-signature-perl prompt crucial security patches for Debian users. Remain vigilant and protected.
Multiple vulnerabilities were discovered in libmodule-signature-perl, a Perl module to manipulate CPAN SIGNATURE files

Summary

CVE-2015-3406

John Lightsey discovered that Module::Signature could parses the
unsigned portion of the SIGNATURE file as the signed portion due to
incorrect handling of PGP signature boundaries.

CVE-2015-3407

John Lightsey discovered that Module::Signature incorrectly handles
files that are not listed in the SIGNATURE file. This includes some
files in the t/ directory that would execute when tests are run.

CVE-2015-3408

John Lightsey discovered that Module::Signature uses two argument
open() calls to read the files when generating checksums from the
signed manifest. This allows to embed arbitrary shell commands into
the SIGNATURE file that would execute during the signature
verification process.

CVE-2015-3409

John Lightsey discovered that Module::Signature incorrectly handles
module loading, allowing to load modules from relative paths in
@INC. A remote attacker providing a malicious module could use this
issue to execute arbitrary code duri...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: libmodule-signature-perl
CVE ID: CVE-2015-3406 CVE-2015-3407 CVE-2015-3408 CVE-2015-3409

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here