CVE-2015-3409
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/05/2015
Last modified:
12/04/2025
Description
Untrusted search path vulnerability in Module::Signature before 0.75 allows local users to gain privileges via a Trojan horse module under the current working directory, as demonstrated by a Trojan horse Text::Diff module.
Impact
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:module-signature_project:module-signature:*:*:*:*:*:*:*:* | 0.74 (including) | |
| cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:* | ||
| cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
| cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:* | ||
| cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://ubuntu.com/usn/usn-2607-1
- http://www.debian.org/security/2015/dsa-3261
- http://www.openwall.com/lists/oss-security/2015/04/07/1
- http://www.openwall.com/lists/oss-security/2015/04/23/17
- http://www.securityfocus.com/bid/73937
- https://github.com/audreyt/module-signature/commit/c41e8885b862b9fce2719449bc9336f0bea658ef
- https://metacpan.org/changes/distribution/Module-Signature
- http://ubuntu.com/usn/usn-2607-1
- http://www.debian.org/security/2015/dsa-3261
- http://www.openwall.com/lists/oss-security/2015/04/07/1
- http://www.openwall.com/lists/oss-security/2015/04/23/17
- http://www.securityfocus.com/bid/73937
- https://github.com/audreyt/module-signature/commit/c41e8885b862b9fce2719449bc9336f0bea658ef
- https://metacpan.org/changes/distribution/Module-Signature



