String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string.
As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)."
This is similar to CVE-2020-36829
Metrics
Affected Vendors & Products
References
History
Fri, 11 Apr 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Fractal
Fractal string\ |
|
Weaknesses | CWE-203 | |
CPEs | cpe:2.3:a:fractal:string\:\:compare\:\:constanttime:*:*:*:*:*:perl:*:* | |
Vendors & Products |
Fractal
Fractal string\ |
Fri, 28 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Fri, 28 Mar 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)." This is similar to CVE-2020-36829 | |
Title | String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string | |
Weaknesses | CWE-208 | |
References |
|

Status: PUBLISHED
Assigner: CPANSec
Published: 2025-03-28T02:05:01.416Z
Updated: 2025-03-28T14:08:55.354Z
Reserved: 2025-03-26T14:18:41.024Z
Link: CVE-2024-13939

Updated: 2025-03-28T14:08:29.495Z

Status : Analyzed
Published: 2025-03-28T03:15:15.720
Modified: 2025-04-11T18:10:56.160
Link: CVE-2024-13939

No data.