Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-22376

Опубликовано: 03 янв. 2025
Источник: debian

Описание

In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libnet-oauth-perlfixed0.30-1package
libnet-oauth-perlno-dsabookwormpackage
libnet-oauth-perlpostponedbullseyepackage

Примечания

  • Fixed by: https://github.com/keeth/Net-OAuth/commit/2aa25e04aadab247ae4063363fcee177161e1f42 (0.29)

  • Followup (bugfix): https://github.com/keeth/Net-OAuth/commit/2276807dbdd5c0cee2d09679e084c7fdfb401704 (0.30)

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 года назад

In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.

CVSS3: 4.8
redhat
около 1 года назад

In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.

CVSS3: 5.3
nvd
около 1 года назад

In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.

CVSS3: 9.8
github
около 1 года назад

In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong.

Уязвимость CVE-2025-22376