Improper Verification of Cryptographic Signature in CPAN - CVE-2020-16156

 

Improper Verification of Cryptographic Signature in CPAN - CVE-2020-16156

Published: October 24, 2022


Vulnerability identifier: #VU68606
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16156
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect processing of signed code. A remote attacker trick the victim into downloading a malicious file, bypass signature verification procedure and compromise the affected system.


Affected software

CPAN
Netcool Operations Insight
Communications Unified Assurance
Juniper Secure Analytics (JSA)
IBM Qradar SIEM
Dell Enterprise SONiC Distribution
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Anolis OS
Ubuntu
Fedora
perl (Ubuntu package)
perl-CPAN (Red Hat package)
perl-CPAN-doc
perl-CPAN
cflinuxfs3
OpenManage Network Integration (OMNI)
HPE Moonshot 1500 Chassis Manager

How to mitigate CVE-2020-16156

Install updates from vendor's website.

CPAN - update to 2.29
Netcool Operations Insight - update to 1.6.15
Juniper Secure Analytics (JSA) - update to 7.5.0 UP12 IF03
IBM Qradar SIEM - update to 7.5.0 Update Pack 12 IF03
perl (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 5.26.1-6ubuntu0.6, 5.30.0-9ubuntu0.3, 5.34.0-3ubuntu1.1, 5.34.0-5ubuntu1.1
cflinuxfs3 - update to 0.329.0
perl-CPAN (Red Hat package) - update to 2.18-402.el8_10
perl-CPAN-doc - update to 2.18-402.0.1
perl-CPAN - update to 2.18-402.0.1
perl-CPAN - addressed in versions 2.29-1.fc34, 2.29-1.fc35
OpenManage Network Integration (OMNI) - update to 3.7
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
Dell Enterprise SONiC Distribution - update to 4.4.2

External References

Related Security Bulletins