Untriaged
Permalink
CVE-2025-40914
9.8 CRITICAL
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow
Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow. CryptX embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.
References
Affected products
CryptX
- =<0.086
Matching in nixpkgs
pkgs.perlPackages.CryptX
Cryptographic toolkit
-
nixos-unstable -
- nixpkgs-unstable 0.087
pkgs.perl538Packages.CryptX
Cryptographic toolkit
-
nixos-unstable -
- nixpkgs-unstable 0.087
pkgs.perl540Packages.CryptX
Cryptographic toolkit
-
nixos-unstable -
- nixpkgs-unstable 0.087