HomeDefault status
unaffected
Any version
affected
Description
Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.
Problem types
CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
Product status
Any version
References
metacpan.org/...PasswdMD5-1.42/source/lib/Crypt/PasswdMD5.pm