UbuntuUpdates.org

Package "libmodule-signature-perl"

Name: libmodule-signature-perl

Description:

module to manipulate CPAN SIGNATURE files

Latest version: 0.73-1ubuntu0.14.04.1
Release: trusty (14.04)
Level: security
Repository: main
Homepage: https://metacpan.org/release/Module-Signature/

Links


Download "libmodule-signature-perl"


Other versions of "libmodule-signature-perl" in Trusty

Repository Area Version
base main 0.73-1
updates main 0.73-1ubuntu0.14.04.1

Changelog

Version: 0.73-1ubuntu0.14.04.1 2015-05-12 14:06:33 UTC

  libmodule-signature-perl (0.73-1ubuntu0.14.04.1) trusty-security; urgency=medium

  * SECURITY UPDATE: arbitrary code execution and incorrect signature
    verification
    - debian/patches/CVE-2015-340x.patch: properly handle temp files and
      headers in lib/Module/Signature.pm, Makefile.PL.
    - debian/patches/CVE-2015-3409.patch: don't load modules from relative
      paths in lib/Module/Signature.pm.
    - CVE-2015-3406
    - CVE-2015-3407
    - CVE-2015-3408
    - CVE-2015-3409
 -- Marc Deslauriers <email address hidden> Fri, 24 Apr 2015 11:58:37 -0400

CVE-2015-3409 arbitrary modules loading in some circumstances
CVE-2015-3406 unsigned files interpreted as signed in some circumstances
CVE-2015-3407 arbitrary code execution during test phase
CVE-2015-3408 arbitrary code execution when verifying module signatures



About   -   Send Feedback to @ubuntu_updates