CVE-2025-1860

Data::Entropy for Perl 0.007 and earlier use the rand() function as the default source of entropy, which is notcryptographically secure,for cryptographic functions.
PRNG
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.7 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CPANSecCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.7 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
Debian logo
Debian Releases
Debian Product
Codename
libdata-entropy-perl
bullseye
vulnerable
bullseye (security)
0.007-3.1+deb11u1
fixed
bookworm
0.007-4+deb12u1
fixed
sid
0.008-1
fixed
trixie
0.008-1
fixed