Описание
Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks.
These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash.
EPSS
Процентиль: 31%
0.00393
Низкий
7.5 High
CVSS3
Дефекты
CWE-208
Связанные уязвимости
CVSS3: 7.5
ubuntu
3 месяца назад
Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash.
CVSS3: 7.5
debian
3 месяца назад
Crypt::SaltedHash versions through 0.09 for Perl is susceptible to tim ...
CVSS3: 7.5
github
3 месяца назад
Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash.
EPSS
Процентиль: 31%
0.00393
Низкий
7.5 High
CVSS3
Дефекты
CWE-208