Net::NSCA::Client versions through 0.009002 for Perl uses...
Critical severity
Unreviewed
Published
Mar 5, 2026
to the GitHub Advisory Database
•
Updated Mar 5, 2026
Description
Published by the National Vulnerability Database
Mar 5, 2026
Published to the GitHub Advisory Database
Mar 5, 2026
Last updated
Mar 5, 2026
Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator.
Version v0.003 switched to use Data::Rand::Obscure instead of Crypt::Random for generation of a random initialisation vectors.
Data::Rand::Obscure uses Perl's built-in rand() function, which is not suitable for cryptographic functions.
References