Improper Certificate Validation in CPAN - CVE-2023-31484

 

Improper Certificate Validation in CPAN - CVE-2023-31484

Published: May 1, 2023


Vulnerability identifier: #VU75604
CSH Severity: Medium
CVSS v4: 7.6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-31484
CWE-ID: CWE-295
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to missing verification of the TLS certificate when downloading distributions. A remote attacker can perform MitM attack and trick the application into downloading a malicious file.


Affected software

CPAN
Amazon Linux AMI
Oracle Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Ubuntu
macOS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
openEuler
Fedora
Oracle Solaris
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
ObjectScale
PowerStore X
OpenManage Network Integration (OMNI)
EMC ECS
PowerStore T
Platform Automation Toolkit
IBM Cloud Pak for Watson AIOps
EMC Cloud Tiering Appliance
Dell PowerProtect Cyber Recovery
Traffix SDC
Juniper Secure Analytics (JSA)
perl (Ubuntu package)
perl-Package-Constants
perl-Module-Loaded
perl-Locale-Maketext-Simple
perl-ExtUtils-CBuilder
perl-Object-Accessor
perl-Pod-Escapes
perl-IO-Zlib
perl-Time-Piece
perl-ExtUtils-Embed
perl-ExtUtils-Install
perl-CPAN
perl-CPAN-doc
perl-CPAN (Red Hat package)
perl-CPAN-help
perl-CPAN-tests
perl-Module-CoreList
perl
perl-libs
perl-tests
perl-macros
perl-core
perl-devel
perl (Red Hat package)
perl-base
perl-debuginfo
perl-base-32bit-debuginfo
perl-base-32bit
perl-32bit-debuginfo
perl-doc
perl-debugsource
perl-base-debuginfo
perl-help
VMware Tanzu Operations Manager
VMware Tanzu Application Service for VMs
Isolation Segment
QRadar User Behavior Analytics
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Dell Enterprise SONiC Distribution
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
Dell EMC VxRail Appliance
RSA Authentication Manager
IBM CICS TX Advanced
IBM Cognos Analytics

How to mitigate CVE-2023-31484

Install updates from vendor's website.

CPAN - update to 2.35
Dell Data Protection Central - update to 19.10.0-4
Traffix SDC - update to 5.2.0
Juniper Secure Analytics (JSA) - addressed in versions 7.5.0 UP7 IF04, 7.5.0 UP9 IF02
macOS - update to 15.2 24C101
perl (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 5.26.1-6ubuntu0.7, 5.30.0-9ubuntu0.4, 5.34.0-3ubuntu1.2, 5.34.0-5ubuntu1.2, 5.36.0-7ubuntu0.23.04.1
perl-Package-Constants - update to 0.02-299
perl-Module-Loaded - update to 0.08-299
perl-Locale-Maketext-Simple - update to 0.21-299
perl-ExtUtils-CBuilder - update to 0.28.2.6-299
perl-Object-Accessor - update to 0.42-299
ObjectScale - update to 1.4.0
perl-Pod-Escapes - update to 1.04-299
perl-IO-Zlib - update to 1.10-299
perl-Time-Piece - update to 1.20.1-299
perl-ExtUtils-Embed - update to 1.30-299
perl-ExtUtils-Install - update to 1.58-299
perl-CPAN - addressed in versions 1.9800-299, 2.18-397.0.2, 2.36-1
VMware Tanzu Operations Manager - update to 2.10.59
perl-CPAN-doc - addressed in versions 2.18-397.0.2, 2.36-1
perl-CPAN (Red Hat package) - addressed in versions 2.18-399.el8, 2.29-3.el9
perl-CPAN - update to 2.27-4
perl-CPAN-help - update to 2.27-4
perl-CPAN - update to 2.34-1
perl-CPAN-tests - update to 2.36-1
perl-CPAN - addressed in versions 2.36-1.fc37, 2.36-1.fc38
perl-Module-CoreList - update to 2.76.02-299
VMware Tanzu Application Service for VMs - addressed in versions 3.0.14, 4.0.5
Isolation Segment - addressed in versions 3.0.14, 4.0.5
PowerStore X - update to 3.2.1.4-2386214
OpenManage Network Integration (OMNI) - update to 3.7
EMC ECS - update to 3.8.0.5
PowerStore T - update to 4.0.0.2-2365061
QRadar User Behavior Analytics - update to 4.1.14
Dell Enterprise SONiC Distribution - update to 4.4.2
Platform Automation Toolkit - addressed in versions 4.4.32, 5.0.25, 5.1.2
IBM Cloud Pak for Watson AIOps - update to 4.6.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
EMC ViPR SRM - update to 4.10.0.0
perl - addressed in versions 5.16.3-294.44, 5.32.1-477
perl-libs - update to 5.16.3-299
perl-tests - update to 5.16.3-299
perl - update to 5.16.3-299
perl-macros - update to 5.16.3-299
perl-core - update to 5.16.3-299
perl-devel - update to 5.16.3-299
perl (Red Hat package) - update to 5.16.3-299.el7_9.1
perl-base - update to 5.26.1-150000.7.18.1
perl-debuginfo - update to 5.26.1-150000.7.18.1
perl-base-32bit-debuginfo - update to 5.26.1-150000.7.18.1
perl-base-32bit - update to 5.26.1-150000.7.18.1
perl-32bit-debuginfo - update to 5.26.1-150000.7.18.1
perl-doc - update to 5.26.1-150000.7.18.1
perl - update to 5.26.1-150000.7.18.1
perl-debugsource - update to 5.26.1-150000.7.18.1
perl-base-debuginfo - update to 5.26.1-150000.7.18.1
perl-debuginfo - update to 5.28.3-7
perl-help - update to 5.28.3-7
perl-debugsource - update to 5.28.3-7
perl-libs - update to 5.28.3-7
perl-devel - update to 5.28.3-7
perl - update to 5.28.3-7
Dell EMC VxRail Appliance - update to 8.0.120
RSA Authentication Manager - addressed in versions 8.7 SP1 Patch 3, 8.7 SP2 Patch 1
IBM CICS TX Advanced - update to 10.1.0.0 ifix21
IBM Cognos Analytics - addressed in versions 11.2.4 FP3, 12.0.3
Oracle Solaris - update to 11.4 SRU 62
EMC Cloud Tiering Appliance - update to 13.1.0.2.33
Dell PowerProtect Cyber Recovery - update to 19.14.0.2

External References

Related Security Bulletins