Описание
Security update for perl-Crypt-PasswdMD5
This update for perl-Crypt-PasswdMD5 fixes the following issues:
Changes in perl-Crypt-PasswdMD5:
-
updated to 1.430.0 (1.43) see /usr/share/doc/packages/perl-Crypt-PasswdMD5/Changelog.ini
[V 1.43] Date=2026-05-23T08:14:00 Deploy.Action=Upgrade Deploy.Reason=Security Comments= <<EOT
- Accept pull request from Paul Howarth to replace use of the cryptographically weak rand() function with the much stronger Crypt::URandom::urandom(). With thanx. CVE-2026-6659 bsc#1264705
- Add Encode, Exporter, ExtUtils::MakeMaker to Makefile.PL.
- Add files AI_POLICY.md & SECURITY.md.
- Delete file LICENSE.
- Add file LICENSE-GPL-3 with the latest version from https://fsf.org/. EOT
Список пакетов
openSUSE Leap 16.0
perl-Crypt-PasswdMD5-1.430.0-bp160.1.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1264705
- SUSE CVE CVE-2026-6659 page
Описание
Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.
Затронутые продукты
openSUSE Leap 16.0:perl-Crypt-PasswdMD5-1.430.0-bp160.1.1
Ссылки
- CVE-2026-6659
- SUSE Bug 1264705