๐Ÿ” CVE Alert

CVE-2017-20240

UNKNOWN 0.0

Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.

CWE CWE-208
Vendor arodland
Product crypt::pbkdf2
Published Jun 12, 2026
Stay Ahead of the Next One

Get instant alerts for arodland crypt::pbkdf2

Be the first to know when new unknown vulnerabilities affecting arodland crypt::pbkdf2 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

ARODLAND / Crypt::PBKDF2
0 < 0.261630

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/arodland/Crypt-PBKDF2/pull/6 metacpan.org: https://metacpan.org/release/ARODLAND/Crypt-PBKDF2-0.161520/source/lib/Crypt/PBKDF2.pm#L123-148 metacpan.org: https://metacpan.org/release/ARODLAND/Crypt-PBKDF2-0.261630/changes