[Bug 2035273] CVE-2020-16156 perl-CPAN: Bypass of verification of signatures in CHECKSUMS files

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



https://bugzilla.redhat.com/show_bug.cgi?id=2035273



--- Comment #4 from Tomas Hoger <thoger@xxxxxxxxxx> ---
Note that the Module::Signature module that is used by both perl-CPAN and
perl-App-cpanminus to perform verification of signatures from the CHECKSUMS
files is not shipped with Red Hat Enterprise Linux 8.  It is shipped with Red
Hat Enterprise Linux 7, but is not installed as a dependency when installing
perl-CPAN, it is only required by perl-App-cpanminus.

When Module::Signature is not installed, both cpan and cpanm skip signature
verification and continue with package installation without verification even
when configured to performed verification (using check_sigs configuration
option for cpan, or --verify command line option for cpanm).


-- 
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2035273
_______________________________________________
perl-devel mailing list -- perl-devel@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to perl-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/perl-devel@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure




[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Legacy Announce]     [Fedora PHP Devel]     [Kernel Devel]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite Information]

  Powered by Linux