Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.
{ "binaries": [ { "binary_version": "1.3-10", "binary_name": "libcrypt-passwdmd5-perl" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-6659.json"
{ "binaries": [ { "binary_version": "1.40-1", "binary_name": "libcrypt-passwdmd5-perl" } ] }
{ "binaries": [ { "binary_version": "1.41-1", "binary_name": "libcrypt-passwdmd5-perl" } ] }
{ "binaries": [ { "binary_version": "1.42-2", "binary_name": "libcrypt-passwdmd5-perl" } ] }