Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.BUGS.DIST
  • Bug#1101502: libstring-compare-constanttime-perl: CVE-2024-13939

    From =?UTF-8?Q?Moritz_M=C3=BChlenhoff?=@21:1/5 to All on Fri Mar 28 15:50:01 2025
    Source: libstring-compare-constanttime-perl
    X-Debbugs-CC: team@security.debian.org
    Severity: important
    Tags: security

    Hi,

    The following vulnerability was published for libstring-compare-constanttime-perl.

    CVE-2024-13939[0]:
    | String::Compare::ConstantTime for Perl through 0.321 is vulnerable
    | to timing attacks that allow an attacker to guess the length of a
    | secret string. As stated in the documentation: "If the lengths of
    | the strings are different, because equals returns false right away
    | the size of the secret string may be leaked (but not its contents)."
    | This is similar to CVE-2020-36829

    https://metacpan.org/release/FRACTAL/String-Compare-ConstantTime-0.321/view/lib/String/Compare/ConstantTime.pm#TIMING-SIDE-CHANNEL


    If you fix the vulnerability please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2024-13939
    https://www.cve.org/CVERecord?id=CVE-2024-13939

    Please adjust the affected versions in the BTS as needed.

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Sylvain Beucler@21:1/5 to All on Sat Apr 12 11:40:01 2025
    The project has been dormant since 2019, but there's a patch proposal: https://github.com/hoytech/String-Compare-ConstantTime/pull/21

    Cheers!
    Sylvain Beucler
    Debian LTS Team

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • Recent Visitors

    • Bob Worm
      Tue May 27 12:05:35 2025
      from Wales, Uk via Telnet
    • Gwylbert
      Tue May 27 10:13:51 2025
      from Sydney, Nsw via Telnet
    • Bob Worm
      Mon May 26 21:35:33 2025
      from Wales, Uk via Telnet
    • Centurion
      Mon May 26 19:02:17 2025
      from Berea, Ohio via Telnet
    • Plume
      Mon May 26 15:58:23 2025
      from Uk via SSH
    • Cvt
      Mon May 26 14:55:38 2025
      from Sofia via Telnet
    • Plume
      Mon May 26 01:37:32 2025
      from Uk via SSH
    • Bob Worm
      Sun May 25 23:29:39 2025
      from Wales, Uk via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 483
    Nodes: 16 (2 / 14)
    Uptime: 130:53:33
    Calls: 9,585
    Calls today: 2
    Files: 13,673
    Messages: 6,146,874

© >>> Magnum BBS <<<, 2025