Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.BUGS.DIST
  • Bug#1109405: libplack-middleware-session-perl: CVE-2025-40923

    From Salvatore Bonaccorso@21:1/5 to All on Wed Jul 16 21:40:01 2025
    Source: libplack-middleware-session-perl
    Version: 0.34-1
    Severity: important
    Tags: security upstream
    Forwarded: https://github.com/plack/Plack-Middleware-Session/pull/52 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

    Hi,

    The following vulnerability was published for libplack-middleware-session-perl.

    CVE-2025-40923[0]:
    | Plack-Middleware-Session before version 0.35 for Perl generates
    | session ids insecurely. The default session id generator returns a
    | SHA-1 hash seeded with the built-in rand function, the epoch time,
    | and the PID. The PID will come from a small set of numbers, and the
    | epoch time may be guessed, if it is not leaked from the HTTP Date
    | header. The built-in rand function is unsuitable for cryptographic
    | usage. Predicable session ids could allow an attacker to gain
    | access to systems.


    If you fix the vulnerability please also make sure to include the
    CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

    For further information see:

    [0] https://security-tracker.debian.org/tracker/CVE-2025-40923
    https://www.cve.org/CVERecord?id=CVE-2025-40923
    [1] https://github.com/plack/Plack-Middleware-Session/pull/52
    [2] https://lists.security.metacpan.org/cve-announce/msg/31223483/
    [3] https://github.com/plack/Plack-Middleware-Session/commit/1fbfbb355e34e7f4b3906f66cf958cedadd2b9be

    Please adjust the affected versions in the BTS as needed.

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • Who's Online

  • Recent Visitors

    • Krenn
      Tue Jun 9 11:18:15 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Tue Jun 9 10:31:07 2026
      from Wales, Uk via Telnet
    • Centurion
      Mon Jun 8 23:30:43 2026
      from Berea, Ohio via Telnet
    • Centurion
      Mon Jun 8 21:33:11 2026
      from Berea, Ohio via Telnet
    • Bob Worm
      Mon Jun 8 20:15:00 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 16:33:22 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 14:11:46 2026
      from Wales, Uk via Telnet
    • Krenn
      Mon Jun 8 11:22:02 2026
      from Sydney, Nsw via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 44:19:21
    Calls: 12,111
    Calls today: 2
    Files: 15,010
    Messages: 6,518,458

© >>> Magnum BBS <<<, 2026