Aggregator

perl-Crypt-PBKDF2-0.261630-1.fc44

1 week 1 day ago
FEDORA-2026-5b12cc327e Packages in this update:
  • perl-Crypt-PBKDF2-0.261630-1.fc44
Update description:

This update addresses a number of security issues:

  • Change the default hash algorithm to HMAC-SHA256, and increase the default number of iterations to 600,000, in line with current OWASP recommendations (CVE-2026-9641)
  • Generate salts using Crypt::URandom (a strong system RNG) instead of perl's builtin rand(), which is not cryptographically secure (CVE-2026-9638)
  • Use a constant-time comparison in validate to avoid timing attacks (CVE-2017-20240)

perl-Crypt-PBKDF2-0.261630-1.el10_3

1 week 1 day ago
FEDORA-EPEL-2026-02984212ed Packages in this update:
  • perl-Crypt-PBKDF2-0.261630-1.el10_3
Update description:

This update addresses a number of security issues:

  • Change the default hash algorithm to HMAC-SHA256, and increase the default number of iterations to 600,000, in line with current OWASP recommendations (CVE-2026-9641)
  • Generate salts using Crypt::URandom (a strong system RNG) instead of perl's builtin rand(), which is not cryptographically secure (CVE-2026-9638)
  • Use a constant-time comparison in validate to avoid timing attacks (CVE-2017-20240)

perl-Crypt-PBKDF2-0.261630-1.el10_2

1 week 1 day ago
FEDORA-EPEL-2026-ee9885ce31 Packages in this update:
  • perl-Crypt-PBKDF2-0.261630-1.el10_2
Update description:

This update addresses a number of security issues:

  • Change the default hash algorithm to HMAC-SHA256, and increase the default number of iterations to 600,000, in line with current OWASP recommendations (CVE-2026-9641)
  • Generate salts using Crypt::URandom (a strong system RNG) instead of perl's builtin rand(), which is not cryptographically secure (CVE-2026-9638)
  • Use a constant-time comparison in validate to avoid timing attacks (CVE-2017-20240)

perl-Crypt-PBKDF2-0.261630-1.el9

1 week 1 day ago
FEDORA-EPEL-2026-c5b8fc5fd2 Packages in this update:
  • perl-Crypt-PBKDF2-0.261630-1.el9
Update description:

This update addresses a number of security issues:

  • Change the default hash algorithm to HMAC-SHA256, and increase the default number of iterations to 600,000, in line with current OWASP recommendations (CVE-2026-9641)
  • Generate salts using Crypt::URandom (a strong system RNG) instead of perl's builtin rand(), which is not cryptographically secure (CVE-2026-9638)
  • Use a constant-time comparison in validate to avoid timing attacks (CVE-2017-20240)

perl-Crypt-PBKDF2-0.261630-1.fc43

1 week 1 day ago
FEDORA-2026-e8231b773d Packages in this update:
  • perl-Crypt-PBKDF2-0.261630-1.fc43
Update description:

This update addresses a number of security issues:

  • Change the default hash algorithm to HMAC-SHA256, and increase the default number of iterations to 600,000, in line with current OWASP recommendations (CVE-2026-9641)
  • Generate salts using Crypt::URandom (a strong system RNG) instead of perl's builtin rand(), which is not cryptographically secure (CVE-2026-9638)
  • Use a constant-time comparison in validate to avoid timing attacks (CVE-2017-20240)