Improper Verification of Cryptographic Signature in CPAN - CVE-2020-16156
Published: October 24, 2022
Vulnerability identifier: #VU68606
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16156
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to incorrect processing of signed code. A remote attacker trick the victim into downloading a malicious file, bypass signature verification procedure and compromise the affected system.
Affected software
CPAN
Netcool Operations Insight
Communications Unified Assurance
Juniper Secure Analytics (JSA)
IBM Qradar SIEM
Dell Enterprise SONiC Distribution
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Anolis OS
Ubuntu
Fedora
perl (Ubuntu package)
perl-CPAN (Red Hat package)
perl-CPAN-doc
perl-CPAN
cflinuxfs3
OpenManage Network Integration (OMNI)
HPE Moonshot 1500 Chassis Manager
Netcool Operations Insight
Communications Unified Assurance
Juniper Secure Analytics (JSA)
IBM Qradar SIEM
Dell Enterprise SONiC Distribution
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Anolis OS
Ubuntu
Fedora
perl (Ubuntu package)
perl-CPAN (Red Hat package)
perl-CPAN-doc
perl-CPAN
cflinuxfs3
OpenManage Network Integration (OMNI)
HPE Moonshot 1500 Chassis Manager
How to mitigate CVE-2020-16156
Install updates from vendor's website.
CPAN - update to 2.29
Netcool Operations Insight - update to 1.6.15
Juniper Secure Analytics (JSA) - update to 7.5.0 UP12 IF03
IBM Qradar SIEM - update to 7.5.0 Update Pack 12 IF03
perl (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 5.26.1-6ubuntu0.6, 5.30.0-9ubuntu0.3, 5.34.0-3ubuntu1.1, 5.34.0-5ubuntu1.1
cflinuxfs3 - update to 0.329.0
perl-CPAN (Red Hat package) - update to 2.18-402.el8_10
perl-CPAN-doc - update to 2.18-402.0.1
perl-CPAN - update to 2.18-402.0.1
perl-CPAN - addressed in versions 2.29-1.fc34, 2.29-1.fc35
OpenManage Network Integration (OMNI) - update to 3.7
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
Dell Enterprise SONiC Distribution - update to 4.4.2
Netcool Operations Insight - update to 1.6.15
Juniper Secure Analytics (JSA) - update to 7.5.0 UP12 IF03
IBM Qradar SIEM - update to 7.5.0 Update Pack 12 IF03
perl (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 5.26.1-6ubuntu0.6, 5.30.0-9ubuntu0.3, 5.34.0-3ubuntu1.1, 5.34.0-5ubuntu1.1
cflinuxfs3 - update to 0.329.0
perl-CPAN (Red Hat package) - update to 2.18-402.el8_10
perl-CPAN-doc - update to 2.18-402.0.1
perl-CPAN - update to 2.18-402.0.1
perl-CPAN - addressed in versions 2.29-1.fc34, 2.29-1.fc35
OpenManage Network Integration (OMNI) - update to 3.7
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
Dell Enterprise SONiC Distribution - update to 4.4.2
External References
- https://metacpan.org/pod/distribution/CPAN/scripts/cpan
- https://blog.hackeriet.no/cpan-signature-verification-vulnerabilities/
- http://blogs.perl.org/users/neilb/2021/11/addressing-cpan-vulnerabilities-related-to-checksums.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SZ32AJIV4RHJMLWLU5QULGKMMIHYOMDC/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SD6RYOJII7HRJ6WVORFNVTYNOFY5JDXN/
Related Security Bulletins
- Signature verification bypass in CPAN
- Ubuntu update for perl
- Cloud Foundry Foundation cflinuxfs3 update for Git
- Ubuntu update for perl
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in HPE Moonshot 1500 Chassis Manager
- Fedora 35 update for perl-CPAN
- Fedora 34 update for perl-CPAN
- Multiple vulnerabilities in Dell OpenManage Network Integration (OMNI)
- Multiple vulnerabilities in Dell Enterprise SONiC Distribution
- Red Hat Enterprise Linux 8 update for perl-CPAN
- Anolis OS update for perl-CPAN
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Secure Analytics
- Multiple vulnerabilities in Netcool Operations Insight