https://bugzilla.redhat.com/show_bug.cgi?id=2495886
Bug ID: 2495886
Summary: CVE-2026-56016 perl-CGI-Session: perl-CGI-Session:
Authentication bypass via predictable session IDs
[fedora-all]
Product: Fedora
Version: rawhide
Status: NEW
Whiteboard: {"flaws": ["9350baf0-9378-4a94-9dd5-30260596865e"]}
Component: perl-CGI-Session
Keywords: Security, SecurityTracking
Severity: high
Priority: high
Assignee: [email protected]
Reporter: [email protected]
QA Contact: [email protected]
CC: [email protected], [email protected]
Blocks: 2495858
Target Milestone: ---
Classification: Fedora
Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.
CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable
session ids from low-entropy sources.
The generate_id method builds the session id from a MD5 digest of the process
id, the epoch time, and the built-in rand() function. All three are
predictable, low-entropy sources: the PID is drawn from a small range, the
epoch time can be guessed or read from the HTTP Date header, and Perl's rand()
is unsuitable for security purposes because it is predictable and reversible.
An attacker who predicts a session id can impersonate the corresponding session
and bypass authentication.
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2495886
Report this comment as SPAM:
https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-spam&short_desc=Report%20of%20Bug%202495886%23c0
--
_______________________________________________
perl-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct:
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it:
https://forge.fedoraproject.org/infra/tickets/issues/new