libmodule-signature-perl: multiple vulnerabilities
Package(s): | libmodule-signature-perl | CVE #(s): | CVE-2015-3406 CVE-2015-3407 CVE-2015-3408 CVE-2015-3409 | ||||||||||||||||||||
Created: | May 12, 2015 | Updated: | January 19, 2016 | ||||||||||||||||||||
Description: | From the Ubuntu advisory:
John Lightsey discovered that Module::Signature incorrectly handled PGP signature boundaries. A remote attacker could use this issue to trick Module::Signature into parsing the unsigned portion of the SIGNATURE file as the signed portion. (CVE-2015-3406) John Lightsey discovered that Module::Signature incorrectly handled files that were not listed in the SIGNATURE file. A remote attacker could use this flaw to execute arbitrary code when tests were run. (CVE-2015-3407) John Lightsey discovered that Module::Signature incorrectly handled embedded shell commands in the SIGNATURE file. A remote attacker could use this issue to execute arbitrary code during signature verification. (CVE-2015-3408) John Lightsey discovered that Module::Signature incorrectly handled module loading. A remote attacker could use this issue to execute arbitrary code during signature verification. (CVE-2015-3409) | ||||||||||||||||||||||
Alerts: |
|