VYPR

rpm package

opensuse/perl-Authen-SASL&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/perl-Authen-SASL&distro=openSUSE%20Tumbleweed

Vulnerabilities (2)

  • CVE-2026-86219CriSep 6, 2026
    affected < 2.210.0-1.1fixed 2.210.0-1.1

    Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh nonce and sends it in the challenge, and nothing later compares that value against the nonce the client ret

  • CVE-2025-40918MedJul 16, 2025
    affected < 2.180.0-2.1fixed 2.180.0-2.1

    Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will come from a small set of numbers, and the epoch t