CVE-2013-2145
Publication date 6 June 2013
Last updated 24 July 2024
Ubuntu priority
The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a “special unknown cipher” that references an untrusted module in Digest/.
Status
Package | Ubuntu Release | Status |
---|---|---|
libmodule-signature-perl | 13.04 raring |
Fixed 0.68-1ubuntu0.13.04.1
|
12.10 quantal |
Fixed 0.68-1ubuntu0.12.10.1
|
|
12.04 LTS precise |
Fixed 0.68-1ubuntu0.12.04.1
|
|
10.04 LTS lucid | Ignored end of life |
Patch details
Package | Patch details |
---|---|
libmodule-signature-perl |
References
Related Ubuntu Security Notices (USN)
- USN-1896-1
- Module::Signature perl module vulnerability
- 3 July 2013