Executive brief
Crypt::DSA is a Perl library used for creating and verifying digital signatures. A security flaw in how the library handles file operations allows for the unintended modification of existing files on the system. This could potentially lead to data corruption or unauthorized changes to sensitive configuration files if an attacker can influence the file paths used by the library.
Technical details
The Crypt::DSA library (specifically in lib/Crypt/DSA/Key.pm) utilizes the legacy Perl 2-argument open() function instead of the secure 3-argument version. This vulnerability class, often associated with CWE-552, occurs because the 2-argument form of open() interprets special characters (like '>' or '|') in the filename string, which can be exploited to truncate or overwrite existing files. An attacker who can control the filename passed to key loading or saving functions could potentially modify arbitrary files with the permissions of the Perl process. The issue is addressed in version 1.20.
Affected products
- Perl CPAN Crypt::DSA through 1.19
Timeline
- 2026-05-15: disclosed: CVE published to NVD
- 2026-05-15: patched: Version 1.20 released to address the issue