Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow.
CryptX embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade perl-CryptX-debuginfoUpgrade perl-CryptX-testsUpgrade perl-CryptX-debugsourceUpgrade perl-CryptX | Jun 24, 2025 | Jun 11, 2025 |
| Debian | — | No solution exists | Jun 13, 2025 | Jun 11, 2025 |
| Suse | — | Upgrade openQA-python-scriptsUpgrade openQA-docUpgrade openQA-bootstrapUpgrade os-autoinstUpgrade os-autoinst-s390-depsUpgrade perl-MojoliciousUpgrade perl-CryptXUpgrade openQAUpgrade openQA-clientUpgrade openQA-auto-updateUpgrade os-autoinst-ipmi-depsUpgrade openQA-single-instanceUpgrade perl-IPC-RunUpgrade openQA-workerUpgrade openQA-continuous-updateUpgrade os-autoinst-qemu-x86Upgrade perl-MCPUpgrade os-autoinst-swtpmUpgrade openQA-local-dbUpgrade os-autoinst-develUpgrade os-autoinst-openvswitchUpgrade openQA-single-instance-nginxUpgrade openQA-develUpgrade openQA-muninUpgrade perl-JSON-ValidatorUpgrade openQA-mcpUpgrade os-autoinst-qemu-kvmUpgrade openQA-common | Dec 5, 2025 | Dec 5, 2025 |
| Ubuntu | — | Upgrade libcryptx-perl (Ubuntu Pro) | Mar 27, 2026 | Jun 11, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub