Security Advisories (1)
CVE-2013-2145 (2013-08-19)

The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that references an untrusted module in Digest/.

NAME

cpansign - CPAN signature management utility

SYNOPSIS

cpansig cpansig sign # ditto cpansig verify # verify a signature

DESCRIPTION

TBD. :-)

SEE ALSO

Module::Signature

AUTHORS

Autrijus Tang <autrijus@autrijus.org>

COPYRIGHT

Copyright 2001, 2002 by Autrijus Tang <autrijus@autrijus.org>.

This program is free software; you can redistribute it and/or modify it under the same terms as Perl itself.

See http://www.perl.com/perl/misc/Artistic.html