CVE-2024-13939 is a timing attack vulnerability in String::Compare::ConstantTime for Perl versions through 0.321, affecting the fractal string product. An attacker can exploit this to determine the length of a secret string, though not its contents, due to differences in comparison time when string lengths vary. With a CVSS score of 7.5 (High), this vulnerability has a low attack complexity and high confidentiality impact, requiring no user interaction or privileges. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 0.321CPE match | cpe:2.3:a:fractal:string\:\:compare\:\:constanttime:*:*:*:*:*:perl:*:* | ||
<= 0.321CPE matchmatch criteria | cpe:2.3:a:fractal:string\:\:compare\:\:constanttime:*:*:*:*:*:perl:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.