Prior to version 0.008, the Perl module Data::Entropy relied on Perl's builtin rand function to choose an entropy source. Version 0.008 does away with this need.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-76dbde76fe 2025-04-11 18:19:12.061898+00:00 -------------------------------------------------------------------------------- Name : perl-Data-Entropy Product : Fedora 42 Version : 0.008 Release : 1.fc42 URL : https://metacpan.org/dist/Data-Entropy Summary : Entropy (randomness) management Description : This module maintains a concept of a current selection of entropy source. Algorithms that require entropy, such as those in Data::Entropy::Algorithms, can use the source nominated by this module, avoiding the need for entropy source objects to be explicitly passed around. This is convenient because usually one entropy source will be used for an entire program run and so an explicit entropy source parameter would rarely vary. There is also a default entropy source, avoiding the need to explicitly configure a source at all. -------------------------------------------------------------------------------- Update Information: Prior to version 0.008, the Perl module Data::Entropy relied on Perl's builtin rand function to choose an entropy source. Version 0.008 does away with this need. -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 30 2025 Emmanuel Seyman - 0.008-1 - Update to 0.008, with new maintainer (#2355612) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2355612 - perl-Data-Entropy-0.008 is available https://bugzilla.redhat.com/show_bug.cgi?id=2355612 [ 2 ] Bug #2355706 - CVE-2025-1860 perl-Data-Entropy: Data::Entropy for Perl uses insecure rand() function for cryptographic functions [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2355706 [ 3 ] Bug #2355707 - CVE-2025-1860 perl-Data-Entropy: Data::Entropy for Perl uses insecure rand() function for cryptographic functions [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2355707 [ 4 ] Bug #2355708 - CVE-2025-1860 perl-Data-Entropy: Data::Entropy for Perl uses insecure rand() function for cryptographic functions [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2355708 [ 5 ] Bug #2355709 - CVE-2025-1860 perl-Data-Entropy: Data::Entropy for Perl uses insecure rand() function for cryptographic functions [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2355709 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-76dbde76fe' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The perl module Data::Entropy was using the cryptographically insecure rand() function as default entropy source. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4100-1
Get the latest Linux and open source security news straight to your inbox.