Skip to content

CryptX susceptible to CVE-2023-36328 libtommath

Low
karel-m published GHSA-6fh3-7qjq-8v22 Jun 11, 2025

Package

CryptX (CPAN)

Affected versions

>= 0.002

Patched versions

0.087

Description

CVE-2023-36328 is for libtommath which was fixed with a patch in libtom/libtommath#546 but this does not seem to have been imported into CryptX.

CVE-2025-40914 assigned by CPANSec CNA for this issue. An email was sent to [email protected] by myself on 2 Jun 2025.

Severity

Low

CVE ID

CVE-2025-40914

Weaknesses

Dependency on Vulnerable Third-Party Component

The product has a dependency on a third-party component that contains one or more known vulnerabilities. Learn more on MITRE.