String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string.
As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)."
This is similar to CVE-2020-36829
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 11 Apr 2025 18:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Fractal Fractal string\ | |
| Weaknesses | CWE-203 | |
| CPEs | cpe:2.3:a:fractal:string\:\:compare\:\:constanttime:*:*:*:*:*:perl:*:* | |
| Vendors & Products | Fractal Fractal string\ | 
Fri, 28 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | cvssV3_1 
 
 | 
Fri, 28 Mar 2025 02:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string. As stated in the documentation: "If the lengths of the strings are different, because equals returns false right away the size of the secret string may be leaked (but not its contents)." This is similar to CVE-2020-36829 | |
| Title | String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string | |
| Weaknesses | CWE-208 | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: CPANSec
Published: 2025-03-28T02:05:01.416Z
Updated: 2025-03-28T14:08:55.354Z
Reserved: 2025-03-26T14:18:41.024Z
Link: CVE-2024-13939
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-03-28T14:08:29.495Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-03-28T03:15:15.720
Modified: 2025-04-11T18:10:56.160
Link: CVE-2024-13939
 Redhat
                        Redhat
                    No data.