Description
CryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicode.

CryptX embeds the tomcrypt library. The versions of that library in CryptX before 0.065 may be susceptible to CVE-2019-17362.
Published: 2025-06-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Users should update to version 0.065 or later.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-18140 CryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicode. CryptX embeds the tomcrypt library. The versions of that library in CryptX before 0.065 may be susceptible to CVE-2019-17362.
Ubuntu USN Ubuntu USN USN-8128-1 CryptX vulnerabilities
History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00056}

epss

{'score': 0.00061}


Wed, 11 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Jun 2025 18:00:00 +0000

Type Values Removed Values Added
Description CryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicode. CryptX embeds the tomcrypt library. The versions of that library in CryptX before 0.065 may be susceptible to CVE-2019-17362.
Title CryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicode
Weaknesses CWE-1395
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: CPANSec

Published:

Updated: 2025-06-11T18:44:15.223Z

Reserved: 2025-04-16T09:05:34.361Z

Link: CVE-2025-40912

cve-icon Vulnrichment

Updated: 2025-06-11T18:44:01.081Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-11T18:15:25.550

Modified: 2025-06-12T16:06:20.180

Link: CVE-2025-40912

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses