Post #4007938
2026-07-22 08:43 UTC
@cpansec@fosstodon.org How do I get incorrect/misleading information in a CVE fixed?
Specifically, CVE-2026-13577: "[...] silently falls back to a built-in rand-derived session id when both Math::Random::ISAAC::XS and Crypt::URandom are unavailable" should be "silently falls back to a built-in rand-derived session id when either Math::Random::ISAAC::XS or Crypt::URandom are unavailable."
Or perhaps better: "silently falls back to a built-in rand-derived session id unless both Math::Random::ISAAC::XS and Crypt::URandom are available."
Replies (0)
No replies.