CVE-2017-20240

Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-12 14:16

Updated : 2026-06-17 01:15


NVD link : CVE-2017-20240

Mitre link : CVE-2017-20240

CVE.ORG link : CVE-2017-20240


JSON object : View

Products Affected

No product.

CWE
CWE-208

Observable Timing Discrepancy