CVE-2018-25107
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Dec 29, 2024
Updated: Dec 31, 2024
CWE ID 338
Summary
CVE-2018-25107 is a vulnerability affecting the Crypt::Random::Source package before version 0.13 in Perl. This issue lies in the use of the built-in rand() function as a fallback for generating secure random bits. Unfortunately, rand() is not a reliable source of randomness, leaving the system vulnerable to predictable sequences and potential attacks. Users are advised to upgrade to version 0.13 or later to mitigate this risk and secure their Perl environment.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.