Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6659

Опубликовано: 08 мая 2026
Источник: redhat
CVSS3: 6.1

Описание

Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.

A flaw was found in Crypt::PasswdMD5 for Perl. This component generates insecure random values for cryptographic salts, which are used to strengthen password hashes. The built-in rand function, used for generating these salts, is predictable and not suitable for cryptographic purposes. This vulnerability could allow an attacker to more easily crack password hashes, potentially leading to unauthorized access or information disclosure.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10perlFix deferred
Red Hat Enterprise Linux 6perlFix deferred
Red Hat Enterprise Linux 7perlFix deferred
Red Hat Enterprise Linux 8perlFix deferred
Red Hat Enterprise Linux 8perl:5.32/perlFix deferred
Red Hat Enterprise Linux 9perlFix deferred
Red Hat OpenShift Container Platform 4rhcosFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-338
https://bugzilla.redhat.com/show_bug.cgi?id=2468316Crypt::PasswdMD5: Perl: Crypt::PasswdMD5: Weak cryptographic salts due to predictable random number generation

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.

CVSS3: 7.5
nvd
3 месяца назад

Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.

CVSS3: 7.5
debian
3 месяца назад

Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure ran ...

suse-cvrf
около 1 месяца назад

Security update for perl-Crypt-PasswdMD5

CVSS3: 7.5
github
3 месяца назад

Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.

6.1 Medium

CVSS3