VYPR

Crypt Pbkdf2

by Arodland

Source repositories

CVEs (1)

  • CVE-2017-20240Jun 12, 2026
    risk 0.00cvss epss

    Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.