Linuxsecurity
Fedora 43 and 44 perl-Catalyst-Plugin Vulnerable to Timing Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Versions of Catalyst::Plugin::Authentication for Perl up to 0.10024 are vulnerable to timing attacks, which could allow attackers to guess passwords or hashes. This vulnerability is documented as CVE-2026-5091, published on May 21, 2026. The issue arises from the use of Perl's built-in eq comparison, leading to discrepancies in timing. Version 0.10026 addresses this vulnerability and was released on May 24, 2026. Users of Fedora 43 and 44 are advised to upgrade to this version to mitigate the risk. The vulnerability affects all systems using the affected versions of the plugin. The update can be installed via the dnf update program. Security professionals should prioritize this update to protect against potential exploitation.
Key Points: • Catalyst::Plugin::Authentication versions up to 0.10024 are vulnerable to timing attacks. • CVE-2026-5091 was published on May 21, 2026, detailing the vulnerability. • Version 0.10026 released on May 24, 2026, fixes the timing attack issue.