Home

Description

The Net::EasyTCP package before 0.15 for Perl always uses Perl's builtin rand(), which is not a strong random number generator, for cryptographic keys.

PUBLISHED Reserved 2025-01-02 | Published 2025-01-02 | Updated 2025-01-06 | Assigner mitre




MEDIUM: 5.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

Problem types

CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

References

metacpan.org/release/MNAGUIB/EasyTCP-0.26/changes

github.com/briandfoy/cpan-security-advisory/issues/184

metacpan.org/release/MNAGUIB/EasyTCP-0.15/view/EasyTCP.pm

cve.org (CVE-2002-20002)

nvd.nist.gov (CVE-2002-20002)

Download JSON