Search CVE reports


Toggle filters

1 – 2 of 2 results


CVE-2026-86219

Medium priority
Fixed

Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh nonce and sends it in the challenge, and nothing later...

1 affected package

libauthen-sasl-perl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libauthen-sasl-perl Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-40918

Low priority
Needs evaluation

Authen::SASL::Perl::DIGEST_MD5 versions 2.04 through 2.1800 for Perl generates the cnonce insecurely. The cnonce (client nonce) is generated from an MD5 hash of the PID, the epoch time and the built-in rand function. The PID will...

1 affected package

libauthen-sasl-perl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libauthen-sasl-perl Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages