CVE-2013-2145: Canonical Ubuntu Linux

Medium severity, CVSS 4.4. EPSS: 0.6% chance of exploitation in the next 30 days.

The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that references an untrusted module in Digest/.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 12.10 only; version 13.04 only
  • Opensuse Opensuse: version 11.4 only; version 12.2 only; version 12.3 only
  • Perlmonks Module::signature: up to and including 0.72; version 0.70 only; version 0.71 only

Published 2013-08-19. Last modified 2026-06-16.