Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks.
For example, if Crypt::SecretBuffer was used to store and compare plaintext passwords, then discrepencies in timing could be used to guess the secret password.
References
| Link | Resource |
|---|---|
| https://metacpan.org/release/NERDVANA/Crypt-SecretBuffer-0.019/source/Changes | Product Release Notes |
| http://www.openwall.com/lists/oss-security/2026/04/13/12 | Mailing List Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-04-13 23:16
Updated : 2026-06-17 10:58
NVD link : CVE-2026-5086
Mitre link : CVE-2026-5086
CVE.ORG link : CVE-2026-5086
JSON object : View
Products Affected
nerdvana
- crypt\
CWE
CWE-208
Observable Timing Discrepancy
