Total vulnerabilities in the database
The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that references an untrusted module in Digest/.
Software | From | Fixed in |
---|---|---|
canonical / ubuntu_linux | 13.04 | 13.04.x |
canonical / ubuntu_linux | 12.10 | 12.10.x |
canonical / ubuntu_linux | 12.04 | 12.04.x |
opensuse / opensuse | 12.3 | 12.3.x |
opensuse / opensuse | 11.4 | 11.4.x |
opensuse / opensuse | 12.2 | 12.2.x |
perlmonks / module--signature | - | 0.72.x |
perlmonks / module--signature | 0.70 | 0.70.x |
perlmonks / module--signature | 0.71 | 0.71.x |