Lucene search

K
cveRedhatCVE-2013-2145
HistoryAug 19, 2013 - 11:55 p.m.

CVE-2013-2145

2013-08-1923:55:08
CWE-20
redhat
web.nvd.nist.gov
29
cpansign
signature
module::signature
bypass
code execution
cve-2013-2145
perl
nvd

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.004

Percentile

73.1%

The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a “special unknown cipher” that references an untrusted module in Digest/.

Affected configurations

Nvd
Node
canonicalubuntu_linuxMatch12.04-lts
OR
canonicalubuntu_linuxMatch12.10
OR
canonicalubuntu_linuxMatch13.04
Node
opensuseopensuseMatch11.4
OR
opensuseopensuseMatch12.2
OR
opensuseopensuseMatch12.3
Node
perlmonksmodule\Match\signature
OR
perlmonksmodule\Match\signature0.70
OR
perlmonksmodule\Match\signature0.71
VendorProductVersionCPE
canonicalubuntu_linux12.04cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
canonicalubuntu_linux12.10cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
canonicalubuntu_linux13.04cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*
opensuseopensuse11.4cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
opensuseopensuse12.2cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*
opensuseopensuse12.3cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
perlmonksmodule\cpe:2.3:a:perlmonks:module\:\:signature:*:*:*:*:*:perl:*:*
perlmonksmodule\cpe:2.3:a:perlmonks:module\:\:signature:0.70:*:*:*:*:perl:*:*
perlmonksmodule\cpe:2.3:a:perlmonks:module\:\:signature:0.71:*:*:*:*:perl:*:*

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.004

Percentile

73.1%