CVE-2015-3406
Published Nov 29, 2019The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspec…
Vendor/product archive
4 CVEs tagged to module-signature_project / module-signature — 1 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.
The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspec…
Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demons…
Module::Signature before 0.74 allows remote attackers to execute arbitrary shell commands via a crafted SIGNATURE file which is not properly handled when generating checksums from…
Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.