Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3406

Опубликовано: 05 апр. 2015
Источник: redhat
CVSS2: 5.1

Описание

The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7perl-Module-SignatureWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=1209911perl-Module-Signature: unsigned files interpreted as signed in some circumstances

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.

CVSS3: 7.5
nvd
около 6 лет назад

The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.

CVSS3: 7.5
debian
около 6 лет назад

The PGP signature parsing in Module::Signature before 0.74 allows remo ...

github
больше 3 лет назад

The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.

5.1 Medium

CVSS2