Unrated severityNVD Advisory· Published Aug 19, 2013· Updated Apr 29, 2026
CVE-2013-2145
CVE-2013-2145
Description
The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that references an untrusted module in Digest/.
Affected products
9cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*+ 2 more
- cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:13.04:*:*:*:*:*:*:*
Patches
2cbd06b392a73https://github.com/audreyt/module-signaturevia nvd-ref
575f7bd6ba4chttps://github.com/audreyt/module-signaturevia nvd-ref
Vulnerability mechanics
Synthesis attempt was rejected by the grounding validator. Re-run pending.
References
8- github.com/audreyt/module-signature/commit/575f7bd6ba4cc7c92f841e8758f88a131674ebf2nvdExploitPatch
- github.com/audreyt/module-signature/commit/cbd06b392a73c63159dc5c20ff5b3c8fc88c4896nvdExploitPatch
- lists.opensuse.org/opensuse-updates/2013-07/msg00039.htmlnvd
- lists.opensuse.org/opensuse-updates/2013-07/msg00043.htmlnvd
- www.openwall.com/lists/oss-security/2013/06/05/16nvd
- www.securityfocus.com/bid/60352nvd
- www.ubuntu.com/usn/USN-1896-1nvd
- bugzilla.redhat.com/show_bug.cginvd
News mentions
0No linked articles in our index yet.