Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks.
The check_password method uses the built-in eq operator. This allows discrepancies in timing to be used to guess the underlying hash.
The check_password method uses the built-in eq operator. This allows discrepancies in timing to be used to guess the underlying hash.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
This module has not been updated since 2012. Users should migrate to an alternative solution.
References
History
Mon, 20 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 20 Jul 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allows discrepancies in timing to be used to guess the underlying hash. | |
| Title | Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks | |
| Weaknesses | CWE-208 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-07-20T18:38:21.362Z
Reserved: 2026-04-20T08:08:16.230Z
Link: CVE-2026-6656
Updated: 2026-07-20T18:38:21.362Z
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses