Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-47373

Опубликовано: 20 мая 2026
Источник: debian
EPSS Низкий

Описание

Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libcrypt-saltedhash-perlfixed0.11-1package
libcrypt-saltedhash-perlno-dsatrixiepackage
libcrypt-saltedhash-perlno-dsabookwormpackage
libcrypt-saltedhash-perlpostponedbullseyepackage

Примечания

  • https://lists.security.metacpan.org/cve-announce/msg/40249915/

  • Fixed by: https://github.com/robrwo/perl-Crypt-SaltedHash/commit/c07bfc5c23185b0667233d0f2e1252d81f1f027a (0.10)

EPSS

Процентиль: 32%
0.00393
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash.

CVSS3: 7.5
nvd
3 месяца назад

Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash.

CVSS3: 7.5
github
3 месяца назад

Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash.

suse-cvrf
около 2 месяцев назад

Security update for perl-Crypt-SaltedHash

EPSS

Процентиль: 32%
0.00393
Низкий