Debian Package Tracker
Register | Log in
Subscribe

libcrypt-pbkdf2-perl

Perl implementation of PBKDF2 password hash

Choose email to subscribe with

general
  • source: libcrypt-pbkdf2-perl (main)
  • version: 0.261630-1
  • maintainer: Debian Perl Group (archive) (DMD) (LowNMU)
  • uploaders: Salvatore Bonaccorso [DMD] – Russ Allbery [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 0.161520-1
  • oldstable: 0.161520-2
  • old-p-u: 0.261630-1~deb13u1~deb12u1
  • stable: 0.161520-2
  • stable-p-u: 0.261630-1~deb13u1
  • testing: 0.261630-1
  • unstable: 0.261630-1
versioned links
  • 0.161520-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.161520-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.261630-1~deb13u1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.261630-1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.261630-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libcrypt-pbkdf2-perl
action needed
3 security issues in bullseye high

There are 3 open security issues in bullseye.

3 important issues:
  • CVE-2026-9638: Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.
  • CVE-2026-9641: Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.
  • CVE-2017-20240: Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.
Created: 2026-06-12 Last update: 2026-06-24 00:50
3 low-priority security issues in trixie low

There are 3 open security issues in trixie.

3 issues left for the package maintainer to handle:
  • CVE-2026-9638: (needs triaging) Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.
  • CVE-2026-9641: (needs triaging) Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for legacy systems. These versions default to using 1000 iterations. Depending on the chosen algorithm, 220,000 to 1,400,000 iterations should be used.
  • CVE-2017-20240: (needs triaging) Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq comparison. Discrepancies in timing could be used to guess the underlying derived-key.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-06-12 Last update: 2026-06-24 00:50
news
[rss feed]
  • [2026-06-16] Accepted libcrypt-pbkdf2-perl 0.261630-1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-06-16] Accepted libcrypt-pbkdf2-perl 0.261630-1~deb13u1~deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-06-16] libcrypt-pbkdf2-perl 0.261630-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-12] Accepted libcrypt-pbkdf2-perl 0.261630-1 (source) into unstable (gregor herrmann)
  • [2022-06-17] libcrypt-pbkdf2-perl 0.161520-2 MIGRATED to testing (Debian testing watch)
  • [2022-06-12] Accepted libcrypt-pbkdf2-perl 0.161520-2 (source) into unstable (Jelmer Vernooij) (signed by: Jelmer Vernooij)
  • [2017-08-12] libcrypt-pbkdf2-perl 0.161520-1 MIGRATED to testing (Debian testing watch)
  • [2017-08-07] Accepted libcrypt-pbkdf2-perl 0.161520-1 (source) into unstable (Salvatore Bonaccorso)
  • [2016-02-16] libcrypt-pbkdf2-perl 0.160410-1 MIGRATED to testing (Debian testing watch)
  • [2016-02-11] Accepted libcrypt-pbkdf2-perl 0.160410-1 (source) into unstable (Salvatore Bonaccorso)
  • [2015-05-07] libcrypt-pbkdf2-perl 0.150900-1 MIGRATED to testing (Britney)
  • [2015-05-02] Accepted libcrypt-pbkdf2-perl 0.150900-1 (source all) into unstable (Salvatore Bonaccorso)
  • [2014-09-09] libcrypt-pbkdf2-perl 0.142390-1 MIGRATED to testing (Britney)
  • [2014-09-02] Accepted libcrypt-pbkdf2-perl 0.142390-1 (source all) into unstable (Salvatore Bonaccorso)
  • [2014-04-19] libcrypt-pbkdf2-perl 0.140890-1 MIGRATED to testing (Debian testing watch)
  • [2014-04-13] Accepted libcrypt-pbkdf2-perl 0.140890-1 (source all) (Salvatore Bonaccorso)
  • [2014-02-12] libcrypt-pbkdf2-perl 0.133330-1 MIGRATED to testing (Debian testing watch)
  • [2014-02-05] Accepted libcrypt-pbkdf2-perl 0.133330-1 (source all) (Russ Allbery)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.261630-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing