ALT-PU-2021-4800-1
Package perl-CPAN updated to version 2.29-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
Published: 2020-07-08
BDU:2023-01694
Уязвимость функции Module::Signature::_verify() языка программирования Perl, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Severity: HIGH (7.5)
Vector: AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
Published: 2021-12-13
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2020-16156
CPAN 2.28 allows Signature Verification Bypass.
Severity: HIGH (7.8)
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
References:
- http://blogs.perl.org/users/neilb/2021/11/addressing-cpan-vulnerabilities-related-to-checksums.html
- http://blogs.perl.org/users/neilb/2021/11/addressing-cpan-vulnerabilities-related-to-checksums.html
- https://blog.hackeriet.no/cpan-signature-verification-vulnerabilities/
- https://blog.hackeriet.no/cpan-signature-verification-vulnerabilities/
- FEDORA-2022-84fd87f7eb
- FEDORA-2022-84fd87f7eb
- FEDORA-2022-21e8372c42
- FEDORA-2022-21e8372c42
- https://metacpan.org/pod/distribution/CPAN/scripts/cpan
- https://metacpan.org/pod/distribution/CPAN/scripts/cpan