Vulnerability Name: | CVE-2013-2145 (CCN-84896) | ||||||||||||||||||||||||
Assigned: | 2013-06-06 | ||||||||||||||||||||||||
Published: | 2013-06-06 | ||||||||||||||||||||||||
Updated: | 2018-10-30 | ||||||||||||||||||||||||
Summary: | The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that references an untrusted module in Digest/. | ||||||||||||||||||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P) 3.2 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-2145 Source: SUSE Type: UNKNOWN openSUSE-SU-2013:1178 Source: SUSE Type: UNKNOWN openSUSE-SU-2013:1185 Source: CCN Type: CPAN Web site Module::Signature Source: MLIST Type: UNKNOWN [oss-security] 20130605 CVE-2013-2145: perl Module::Signature code execution vulnerability Source: BID Type: UNKNOWN 60352 Source: CCN Type: BID-60352 Module::Signature CVE-2013-2145 Local Arbitrary Code Execution Vulnerability Source: UBUNTU Type: UNKNOWN USN-1896-1 Source: CCN Type: Red Hat Bugzilla Bug 971096 CVE-2013-2145 perl-Module-Signature: arbitrary code execution when verifying SIGNATURE Source: MISC Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=971096 Source: XF Type: UNKNOWN module-signature-cve20132145-code-exec(84896) Source: CONFIRM Type: Exploit, Patch https://github.com/audreyt/module-signature/commit/575f7bd6ba4cc7c92f841e8758f88a131674ebf2 Source: CONFIRM Type: Exploit, Patch https://github.com/audreyt/module-signature/commit/cbd06b392a73c63159dc5c20ff5b3c8fc88c4896 Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-2145 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: ![]() | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |