CVE-2025-40912 Details
Description
CryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicode. CryptX embeds the tomcrypt library. The versions of that library in CryptX before 0.065 may be susceptible to CVE-2019-17362.
A vulnerability in CryptX for Perl, prior to version 0.065, arises from its embedding of the tomcrypt library, which versions before 0.065 may be vulnerable to improper handling of UTF-8 encoding. This flaw allows context-dependent attackers to cause a denial-of-service by triggering an out-of-bounds read that crashes the application, or to exploit a two-step information disclosure attack by reading data from adjacent memory locations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 11, 2025CISA-ADP
Assessed Jun 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/libtom/libtomcrypt/issues/507 | CPANSec | ExploitIssue TrackingTechnical Description |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| CryptX | All versions |
CPE
Remediation
| |
| libtomcrypt | <= 1.18.2 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CPANSec |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 11, 2025 | CVE Modified | CISA-ADP |
| Jun 11, 2025 | New CVE Received | CPANSec |
Volerion