HomeDefault status
unaffected
Any version before 1.20
affected
Description
Crypt::DSA versions before 1.20 for Perl generate seeds using rand. Seeds were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.
Problem types
Product status
Any version before 1.20
Timeline
| 2026-05-15: | CPANSec identified issue |
| 2026-05-15: | Author was notified |
| 2026-05-15: | Version 1.20 released. |
References
www.openwall.com/lists/oss-security/2026/05/15/26
metacpan.org/release/TIMLEGGE/Crypt-DSA-1.20/changes
metacpan.org/.../Crypt-DSA-1.20/diff/TIMLEGGE/Crypt-DSA-1.19