Описание
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libcrypt-pbkdf2-perl | fixed | 0.261630-1 | package | |
| libcrypt-pbkdf2-perl | fixed | 0.261630-1~deb13u1 | trixie | package |
| libcrypt-pbkdf2-perl | fixed | 0.261630-1~deb13u1~deb12u1 | bookworm | package |
Примечания
https://lists.security.metacpan.org/cve-announce/msg/40933040/
Fixed by: https://github.com/arodland/Crypt-PBKDF2/commit/320db2451c42916ce787479de8a0bb1fb37a6700 (0.261630)
EPSS
Связанные уязвимости
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.
Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.
EPSS