PT-2014-9126 · Perl · Perl-Authen-Captcha
Published
2014-04-09
·
Updated
2014-04-09
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
perl-Authen-Captcha versions prior to the version that includes the fix
Description
The issue concerns the generation of the public string for the captcha, which was previously a checksum of the secret string, making it easy to break. This has been fixed by producing a random filename for the captcha.
Recommendations
For versions prior to the fixed version, update to the new version of perl-Authen-Captcha that produces a random filename for the captcha.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Perl-Authen-Captcha