CVE-2015-3409: High severity module-signature vulnerability
Published May 19, 2015
·Updated
Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff module.
Affected Software
5 affected components
Module-signature Project Module-signature<=0.74
Ubuntu=12.04
Ubuntu=14.04
Ubuntu=14.10
Ubuntu=15.04
Event History
May 19, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3409?
CVE-2015-3409 is considered a local privilege escalation vulnerability.
2
How do I fix CVE-2015-3409?
To fix CVE-2015-3409, upgrade Module::Signature to version 0.75 or later.
3
Who is affected by CVE-2015-3409?
Local users on systems with Module::Signature versions prior to 0.75 are affected by CVE-2015-3409.
4
What type of vulnerability is CVE-2015-3409?
CVE-2015-3409 is an untrusted search path vulnerability.
5
Can CVE-2015-3409 be exploited remotely?
No, CVE-2015-3409 requires local access to the system to be exploited.