CVE detail
CVE-2006-0898 — CVE-2006-0898
Published 2006-02-25 · Modified 2026-06-16 · Vendor lincoln_d._stein · Product crypt_cbc · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0140
EPSS probability
exploitation probability, 30d
70.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Crypt::CBC Perl module 2.16 and earlier, when running in RandomIV mode, uses an initialization vector (IV) of 8 bytes, which results in weaker encryption when used with a cipher that requires a larger block size than 8 bytes, such as Rijndael.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References