VDB

GCVE-110-MAGEIA-2014-167

GCVE-110-MAGEIA-2014-167
Advisory Published
Vulnetix · Advisory published April 9, 2014
An issue in previous versions of perl-Authen-Captcha is that the generated public string (file name of the picture) for the captcha is merely a checksum of the secret string. It is trivial to break such short strings even using google instead of a rainbow table. This new version of perl-Authen-Captcha fixes the problem by producing a random filename for the captcha.

Affected Products

VendorProductVersionsPlatforms
Mageiaperl-Authen-Captcha0 (affected), 1.24.0-1.mga3 (unaffected), 0 (affected), 1.24.0-1.mga3 (unaffected)
Mageiagkrellm-plugins0 (affected), 2.3.5-10.1.mga4 (unaffected)
Mageiaperl-Authen-Captcha0 (affected), 1.24.0-1.mga4 (unaffected), 0 (affected), 1.24.0-1.mga4 (unaffected)

Browse GCVE Records

74,267 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›