CVE-2024-13939
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 28, 2025
Updated: Apr 11, 2025
CWE ID 208
CWE ID 203
Summary
CVE-2024-13939 is a newly disclosed vulnerability affecting the String::Compare::ConstantTime module in Perl up to version 0.321. This issue exposes the length of a secret string through timing attacks, making it possible for attackers to guess its length without accessing its contents. The documentation specifies that if string lengths differ, the equals function returns false immediately, potentially revealing the size of the secret string. This vulnerability shares similarities with CVE-2020-36829.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.