Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

1 – 5 of 5 results


CVE-2015-3409

Medium priority

Some fixes available 4 of 5

Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff module.

1 affected packages

libmodule-signature-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libmodule-signature-perl
Show less packages

CVE-2015-3408

Medium priority

Some fixes available 4 of 5

Module::Signature before 0.74 allows remote attackers to execute arbitrary shell commands via a crafted SIGNATURE file which is not properly handled when generating checksums from a signed manifest.

1 affected packages

libmodule-signature-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libmodule-signature-perl
Show less packages

CVE-2015-3407

Medium priority

Some fixes available 4 of 5

Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.

1 affected packages

libmodule-signature-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libmodule-signature-perl
Show less packages

CVE-2015-3406

Medium priority

Some fixes available 4 of 5

The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.

1 affected packages

libmodule-signature-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libmodule-signature-perl
Show less packages

CVE-2013-2145

Medium priority

Some fixes available 3 of 4

The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that references...

1 affected packages

libmodule-signature-perl

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
libmodule-signature-perl
Show less packages