CVE detail
CVE-2015-3406 — CVE-2015-3406
Published 2019-11-29 · Modified 2026-06-17 · Vendor module-signature_project · Product module-signature · Source nvd
HIGH
severity
CVSS-derived band
0.0229
EPSS probability
exploitation probability, 30d
82.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The PGP signature parsing in Module::Signature before 0.74 allows remote attackers to cause the unsigned portion of a SIGNATURE file to be treated as the signed portion via unspecified vectors.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References