Lucene search

K

Perl Crypt Security Vulnerabilities

cve
cve

CVE-2020-17478

ECDSA/EC/Point.pm in Crypt::Perl before 0.33 does not properly consider timing attacks against the EC point multiplication...

7.5CVSS

7.5AI Score

0.002EPSS

2020-08-10 06:15 PM
32
cve
cve

CVE-2020-13895

Crypt::Perl::ECDSA in the Crypt::Perl (aka p5-Crypt-Perl) module before 0.32 for Perl fails to verify correct ECDSA signatures when r and s are small and when s = 1. This happens when using the curve secp256r1 (prime256v1). This could conceivably have a security-relevant impact if an attacker...

8.8CVSS

8.6AI Score

0.002EPSS

2020-06-07 01:15 AM
91
cve
cve

CVE-2019-1010161

perl-CRYPT-JWT 0.022 and earlier is affected by: Incorrect Access Control. The impact is: bypass authentication. The component is: JWT.pm for JWT security token, line 614 in _decode_jws(). The attack vector is: network connectivity(crafting user-controlled input to bypass authentication). The...

9.8CVSS

9.5AI Score

0.003EPSS

2019-07-25 02:15 PM
33
cve
cve

CVE-2019-1010263

Perl Crypt::JWT prior to 0.023 is affected by: Incorrect Access Control. The impact is: allow attackers to bypass authentication by providing a token by crafting with hmac(). The component is: JWT.pm, line 614. The attack vector is: network connectivity. The fixed version is: after commit...

9.8CVSS

9.6AI Score

0.003EPSS

2019-07-17 09:15 PM
31
cve
cve

CVE-2011-3599

The Crypt::DSA (aka Crypt-DSA) module 1.17 and earlier for Perl, when /dev/random is absent, uses the Data::Random module, which makes it easier for remote attackers to spoof a signature, or determine the signing key of a signed message, via a brute-force...

6.3AI Score

0.004EPSS

2011-10-10 10:55 AM
27