Fedora 21 : perl-Module-Signature-0.78-1.fc21 / perl-Test-Signature-1.11-1.fc21 (2015-5833)

high Nessus Plugin ID 82886

Synopsis

The remote Fedora host is missing one or more security updates.

Description

This update addresses various security issues in perl-Module-Signature as described below. The default behavior is also changed so as to ignore any MANIFEST.SKIP files unless a 'skip' parameter is specified.
An updated version of perl-Test-Signature that accounts for the changed default behavior is included in this update.

Security issues :

- Module::Signature before version 0.75 could be tricked into interpreting the unsigned portion of a SIGNATURE file as the signed portion due to faulty parsing of the PGP signature boundaries.

- When verifying the contents of a CPAN module, Module::Signature before version 0.75 ignored some files in the extracted tarball that were not listed in the signature file. This included some files in the t/ directory that would execute automatically during 'make test'.

- Module::Signature before version 0.75 used two argument open() calls to read the files when generating checksums from the signed manifest. This allowed embedding arbitrary shell commands into the SIGNATURE file that would execute during the signature verification process.

- Module::Signature before version 0.75 has been loading several modules at runtime inside the extracted module directory. Modules like Text::Diff are not guaranteed to be available on all platforms and could be added to a malicious module so that they would load from the '.' path in @INC.

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected perl-Module-Signature and / or perl-Test-Signature packages.

See Also

https://bugzilla.redhat.com/show_bug.cgi?id=1209911

https://bugzilla.redhat.com/show_bug.cgi?id=1209915

https://bugzilla.redhat.com/show_bug.cgi?id=1209917

https://bugzilla.redhat.com/show_bug.cgi?id=1209918

http://www.nessus.org/u?f29d4586

http://www.nessus.org/u?7dc5ca36

Plugin Details

Severity: High

ID: 82886

File Name: fedora_2015-5833.nasl

Version: 1.4

Type: local

Agent: unix

Published: 4/20/2015

Updated: 1/11/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:perl-module-signature, p-cpe:/a:fedoraproject:fedora:perl-test-signature, cpe:/o:fedoraproject:fedora:21

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 4/9/2015

Reference Information

FEDORA: 2015-5833