These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to version 0.261630 or later.
Vendor Workaround
Apply the patch from the referenced pull request.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 12 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arodland
Arodland crypt::pbkdf2 |
|
| Vendors & Products |
Arodland
Arodland crypt::pbkdf2 |
Fri, 12 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 12 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 12 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key. | |
| Title | Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks | |
| Weaknesses | CWE-208 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-06-12T16:59:33.477Z
Reserved: 2026-05-26T18:23:21.387Z
Link: CVE-2017-20240
Updated: 2026-06-12T16:59:33.477Z
Status : Deferred
Published: 2026-06-12T14:16:28.660
Modified: 2026-06-12T17:16:22.133
Link: CVE-2017-20240
No data.
OpenCVE Enrichment
Updated: 2026-06-12T20:20:26Z