Описание
Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks.
These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.
EPSS
Процентиль: 25%
0.00319
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-208
Связанные уязвимости
CVSS3: 5.9
ubuntu
3 месяца назад
Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.
CVSS3: 5.9
debian
3 месяца назад
Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timi ...
CVSS3: 5.9
github
3 месяца назад
Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.
EPSS
Процентиль: 25%
0.00319
Низкий
5.9 Medium
CVSS3
Дефекты
CWE-208