PT-2025-13421 · Unknown+1 · String::Compare::Constanttime+1

·

CVE-2024-13939

·

Published

2025-03-28

·

Updated

2025-04-11

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions String::Compare::ConstantTime versions prior to 0.322
Description The issue allows an attacker to guess the length of a secret string through timing attacks. According to the documentation, if the lengths of the strings are different, the size of the secret string may be leaked when the equals function returns false immediately.
Recommendations For versions prior to 0.322, update to version 0.322 or later to resolve the issue. As a temporary workaround, consider implementing additional measures to prevent timing attacks, such as introducing random delays in string comparisons.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13939

Affected Products

Debian
String::Compare::Constanttime