perl-Catalyst-Plugin-Authentication-0.10026-1.fc43
- perl-Catalyst-Plugin-Authentication-0.10026-1.fc43
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks since these versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. Version 0.10026 of the module fixes this issue.