CVE-2015-3407: Medium severity ubuntu vulnerability
Published May 19, 2015
·Updated
Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.
Affected Software
5 affected components
Ubuntu=12.04
Ubuntu=14.04
Ubuntu=14.10
Ubuntu=15.04
Module-signature Project Module-signature<=0.73
Event History
May 19, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3407?
CVE-2015-3407 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2015-3407?
To fix CVE-2015-3407, you should upgrade Module::Signature to version 0.74 or later.
3
What systems are affected by CVE-2015-3407?
CVE-2015-3407 affects Ubuntu releases 12.04, 14.04, 14.10, and 15.04 with Module::Signature versions up to 0.73.
4
What type of vulnerability is CVE-2015-3407?
CVE-2015-3407 is a remote code execution vulnerability that allows attackers to bypass signature verification.
5
Can CVE-2015-3407 impact system integrity?
Yes, CVE-2015-3407 can undermine system integrity by allowing unauthorized files to be considered legitimate.