Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-20240

Опубликовано: 12 июн. 2026
Источник: debian

Описание

Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libcrypt-pbkdf2-perlfixed0.261630-1package
libcrypt-pbkdf2-perlfixed0.261630-1~deb13u1trixiepackage
libcrypt-pbkdf2-perlfixed0.261630-1~deb13u1~deb12u1bookwormpackage

Примечания

  • https://lists.security.metacpan.org/cve-announce/msg/40929601/

  • Fixed by: https://github.com/arodland/Crypt-PBKDF2/commit/ac5aac7c8c0e411165a6665a9c1f449b745f2629 (0.261630)

Связанные уязвимости

CVSS3: 5.9
ubuntu
3 месяца назад

Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.

CVSS3: 5.9
nvd
3 месяца назад

Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.

CVSS3: 5.9
github
3 месяца назад

Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.