Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-13939

Опубликовано: 28 мар. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string.

As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)."

This is similar to CVE-2020-36829

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:fractal:string\:\:compare\:\:constanttime:*:*:*:*:*:perl:*:*
Версия до 0.321 (включая)

EPSS

Процентиль: 53%
0.00307
Низкий

7.5 High

CVSS3

Дефекты

CWE-208
CWE-203

Связанные уязвимости

CVSS3: 7.5
ubuntu
11 месяцев назад

String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)." This is similar to CVE-2020-36829

CVSS3: 7.5
debian
11 месяцев назад

String::Compare::ConstantTime for Perl through 0.321 is vulnerable to ...

CVSS3: 7.5
github
11 месяцев назад

String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)." This is similar to CVE-2020-36829

EPSS

Процентиль: 53%
0.00307
Низкий

7.5 High

CVSS3

Дефекты

CWE-208
CWE-203