Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-6659

Опубликовано: 08 мая 2026
Источник: debian
EPSS Низкий

Описание

Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libcrypt-passwdmd5-perlfixed1.44-1package
libcrypt-passwdmd5-perlno-dsatrixiepackage
libcrypt-passwdmd5-perlpostponedbookwormpackage
libcrypt-passwdmd5-perlpostponedbullseyepackage

Примечания

  • https://lists.security.metacpan.org/cve-announce/msg/39857355/

  • Fixed by: https://github.com/ronsavage/Crypt-PasswdMD5/commit/a2f821637db0296082297aa4b02254ab08f0dc5e (1.43)

EPSS

Процентиль: 37%
0.00447
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.

CVSS3: 6.1
redhat
3 месяца назад

Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.

CVSS3: 7.5
nvd
3 месяца назад

Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.

suse-cvrf
около 1 месяца назад

Security update for perl-Crypt-PasswdMD5

CVSS3: 7.5
github
3 месяца назад

Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.

EPSS

Процентиль: 37%
0.00447
Низкий