Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-47372

Опубликовано: 20 мая 2026
Источник: debian
EPSS Низкий

Описание

Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libcrypt-saltedhash-perlfixed0.11-1package
libcrypt-saltedhash-perlno-dsatrixiepackage
libcrypt-saltedhash-perlno-dsabookwormpackage
libcrypt-saltedhash-perlpostponedbullseyepackage

Примечания

  • https://lists.security.metacpan.org/cve-announce/msg/40252126/

  • Fixed by: https://github.com/robrwo/perl-Crypt-SaltedHash/commit/9b68437d2cd420b819b3a795474c3870338d38d5 (0.10)

EPSS

Процентиль: 32%
0.00397
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
3 месяца назад

Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.

CVSS3: 9.1
nvd
3 месяца назад

Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.

CVSS3: 9.1
github
3 месяца назад

Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.

suse-cvrf
около 2 месяцев назад

Security update for perl-Crypt-SaltedHash

EPSS

Процентиль: 32%
0.00397
Низкий