CVE-2017-20240

Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.
Configurations

No configuration.

History

12 Jun 2026, 17:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/06/12/3 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9

12 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-12 14:16

Updated : 2026-06-17 01:15


NVD link : CVE-2017-20240

Mitre link : CVE-2017-20240

CVE.ORG link : CVE-2017-20240


JSON object : View

Products Affected

No product.

CWE
CWE-208

Observable Timing Discrepancy