PT-2025-14484 · Unknown · Crypt::Salt
Robert Rothenberg
·
Published
2025-04-02
·
Updated
2025-04-02
·
CVE-2025-1805
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Crypt::Salt for Perl version 0.01
Description
The issue concerns the use of an insecure
rand() function when generating salts for cryptographic purposes. This could potentially lead to weaknesses in the cryptographic mechanisms that rely on these salts.Recommendations
For Crypt::Salt for Perl version 0.01, consider using a more secure random number generator to mitigate the risk associated with the insecure
rand() function. As a temporary workaround, restrict the use of the rand() function in cryptographic contexts until a more secure alternative is implemented. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Crypt::Salt