String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)." This is similar to CVE-2020-36829
History

Fri, 11 Apr 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Fractal
Fractal string\
Weaknesses CWE-203
CPEs cpe:2.3:a:fractal:string\:\:compare\:\:constanttime:*:*:*:*:*:perl:*:*
Vendors & Products Fractal
Fractal string\

Fri, 28 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 02:30:00 +0000

Type Values Removed Values Added
Description String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)." This is similar to CVE-2020-36829
Title String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string
Weaknesses CWE-208
References

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published: 2025-03-28T02:05:01.416Z

Updated: 2025-03-28T14:08:55.354Z

Reserved: 2025-03-26T14:18:41.024Z

Link: CVE-2024-13939

cve-icon Vulnrichment

Updated: 2025-03-28T14:08:29.495Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-28T03:15:15.720

Modified: 2025-04-11T18:10:56.160

Link: CVE-2024-13939

cve-icon Redhat

No data.