CVE-2015-3406
- EPSS 1.27%
- Veröffentlicht 29.11.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 02:29:21
The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.
CVE-2015-3409
- EPSS 0.06%
- Veröffentlicht 19.05.2015 18:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff module.
- EPSS 3.93%
- Veröffentlicht 19.05.2015 18:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Module::Signature before 0.74 allows remote attackers to execute arbitrary shell commands via a crafted SIGNATURE file which is not properly handled when generating checksums from a signed manifest.
- EPSS 0.36%
- Veröffentlicht 19.05.2015 18:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.