Описание
Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libcrypt-passwdmd5-perl | fixed | 1.44-1 | package | |
| libcrypt-passwdmd5-perl | no-dsa | trixie | package | |
| libcrypt-passwdmd5-perl | postponed | bookworm | package | |
| libcrypt-passwdmd5-perl | postponed | bullseye | package |
Примечания
https://lists.security.metacpan.org/cve-announce/msg/39857355/
Fixed by: https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e (1.43)
EPSS
Связанные уязвимости
Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.
Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.
Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.
Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.
EPSS