Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks.
These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.
These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to version 0.261630 or later.
Workaround
Apply the patch from the referenced pull request.
References
History
Fri, 12 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key. | |
| Title | Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks | |
| Weaknesses | CWE-208 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-06-12T13:19:15.900Z
Reserved: 2026-05-26T18:23:21.387Z
Link: CVE-2017-20240
No data.
Status : Received
Published: 2026-06-12T14:16:28.660
Modified: 2026-06-12T14:16:28.660
Link: CVE-2017-20240
No data.
OpenCVE Enrichment
No data.
Weaknesses