CVE-2015-3408

Module::Signature <0.74 - RCE

Title source: llm
STIX 2.1

Description

Module::Signature before 0.74 allows remote attackers to execute arbitrary shell commands via a crafted SIGNATURE file which is not properly handled when generating checksums from a signed manifest.

References (6)

Core 6
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3261
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/04/07/1
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/04/23/17
Various Sources vendor-advisory x_refsource_ubuntu
http://ubuntu.com/usn/usn-2607-1

Scores

EPSS 0.0393
EPSS Percentile 88.4%

Details

CWE
CWE-77
Status published
Products (5)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 14.10
canonical/ubuntu_linux 15.04
module-signature_project/module-signature < 0.73
Published May 19, 2015
Tracked Since Feb 18, 2026