String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string.
As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)."
This is similar to CVE-2020-36829
As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)."
This is similar to CVE-2020-36829
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8542 | String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)." This is similar to CVE-2020-36829 |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Apr 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fractal
Fractal string\ |
|
| Weaknesses | CWE-203 | |
| CPEs | cpe:2.3:a:fractal:string\:\:compare\:\:constanttime:*:*:*:*:*:perl:*:* | |
| Vendors & Products |
Fractal
Fractal string\ |
Fri, 28 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 28 Mar 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)." This is similar to CVE-2020-36829 | |
| Title | String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string | |
| Weaknesses | CWE-208 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2025-03-28T14:08:55.354Z
Reserved: 2025-03-26T14:18:41.024Z
Link: CVE-2024-13939
Updated: 2025-03-28T14:08:29.495Z
Status : Analyzed
Published: 2025-03-28T03:15:15.720
Modified: 2025-04-11T18:10:56.160
Link: CVE-2024-13939
No data.
OpenCVE Enrichment
No data.
EUVD