Логотип exploitDog
bind:CVE-2024-13939
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-13939

Количество 4

Количество 4

ubuntu логотип

CVE-2024-13939

11 месяцев назад

String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)." This is similar to CVE-2020-36829

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-13939

11 месяцев назад

String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)." This is similar to CVE-2020-36829

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-13939

11 месяцев назад

String::Compare::ConstantTime for Perl through 0.321 is vulnerable to ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-x2v7-w9j6-rqmx

11 месяцев назад

String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)." This is similar to CVE-2020-36829

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-13939

String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)." This is similar to CVE-2020-36829

CVSS3: 7.5
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2024-13939

String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)." This is similar to CVE-2020-36829

CVSS3: 7.5
0%
Низкий
11 месяцев назад
debian логотип
CVE-2024-13939

String::Compare::ConstantTime for Perl through 0.321 is vulnerable to ...

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-x2v7-w9j6-rqmx

String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)." This is similar to CVE-2020-36829

CVSS3: 7.5
0%
Низкий
11 месяцев назад

Уязвимостей на страницу