CVE-2015-3406: High severity module-signature vulnerability
Published Nov 29, 2019
·Updated
The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.
Affected Software
5 affected components
Module-signature Project Module-signature<0.74
Ubuntu=12.04
Ubuntu=14.04
Ubuntu=14.10
Ubuntu=15.04
Remediation
Patch Available
Patch Available
Patch Available
Event History
Nov 29, 2019
CVE Published
via MITRE·08:42 PM
Data Sourced
via MITRE·08:42 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3406?
CVE-2015-3406 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-3406?
To fix CVE-2015-3406, upgrade Module::Signature to version 0.74 or later.
3
What software is impacted by CVE-2015-3406?
CVE-2015-3406 affects Module::Signature versions earlier than 0.74 and various Ubuntu Linux distributions.
4
Can CVE-2015-3406 be exploited remotely?
Yes, CVE-2015-3406 can be exploited by remote attackers due to improper PGP signature handling.
5
What happens if CVE-2015-3406 is exploited?
Exploitation of CVE-2015-3406 can lead to the unsigned portion of a SIGNATURE file being mistaken for the signed portion.