Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow.
CryptX embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade perl-CryptX-debuginfoUpgrade perl-CryptX-debugsourceUpgrade perl-CryptX-testsUpgrade perl-CryptX | Jun 24, 2025 | Jun 11, 2025 |
| Debian | — | No solution exists | Jun 13, 2025 | Jun 11, 2025 |
| Suse | — | Upgrade openQAUpgrade perl-CryptXUpgrade openQA-auto-updateUpgrade perl-MojoliciousUpgrade os-autoinstUpgrade os-autoinst-s390-depsUpgrade openQA-bootstrapUpgrade openQA-clientUpgrade os-autoinst-ipmi-depsUpgrade openQA-docUpgrade openQA-python-scriptsUpgrade openQA-single-instanceUpgrade os-autoinst-qemu-x86Upgrade os-autoinst-openvswitchUpgrade perl-IPC-RunUpgrade openQA-workerUpgrade openQA-continuous-updateUpgrade openQA-single-instance-nginxUpgrade openQA-develUpgrade perl-MCPUpgrade os-autoinst-develUpgrade os-autoinst-swtpmUpgrade os-autoinst-qemu-kvmUpgrade openQA-muninUpgrade openQA-commonUpgrade openQA-mcpUpgrade openQA-local-dbUpgrade perl-JSON-Validator | Dec 5, 2025 | Dec 5, 2025 |
| Ubuntu | — | Upgrade libcryptx-perl (Ubuntu Pro) | Mar 27, 2026 | Jun 11, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub