PT-2015-6218 · Perl+1 · Module::Signature+1

John Lightsey

·

Publicado

2015-04-23

·

Atualizado

2024-06-15

·

CVE-2015-3407

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Module::Signature versions prior to 0.74
Description The issue allows remote attackers to bypass signature verification for files. This can be achieved by using a signature file that does not list the files.
Recommendations For versions prior to 0.74, update to version 0.74 or later to resolve the issue. As a temporary workaround, consider validating the contents of signature files to ensure they list all relevant files before proceeding with verification.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-3407
DLA-264-1
DSA-3261-1
DSA-3261-2
OPENSUSE-SU-2024:10458-1
USN-2607-1

Produtos afetados

Module::Signature
Ubuntu