PT-2025-13421 · Unknown+1 · String::Compare::Constanttime+1

Robert Rothenberg

·

Published

2025-03-28

·

Updated

2025-04-11

·

CVE-2024-13939

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions String::Compare::ConstantTime versions prior to 0.322
Description The issue allows an attacker to guess the length of a secret string through timing attacks. According to the documentation, if the lengths of the strings are different, the size of the secret string may be leaked when the equals function returns false immediately.
Recommendations For versions prior to 0.322, update to version 0.322 or later to resolve the issue. As a temporary workaround, consider implementing additional measures to prevent timing attacks, such as introducing random delays in string comparisons.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2024-13939

Affected Products

Debian
String::Compare::Constanttime