
Cloud Vulnerability DB
A community-led vulnerabilities database
CryptX for Perl before version 0.065 contains a dependency vulnerability related to malformed unicode handling. The vulnerability was discovered and disclosed on June 11, 2025. The affected component is the embedded tomcrypt library, which may be susceptible to CVE-2019-17362 (NVD, Ubuntu).
The vulnerability stems from improper detection of invalid UTF-8 sequences in the derdecodeutf8_string function within the tomcrypt library. The vulnerability has received a CVSS v3.1 Base Score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating a critical severity level with network attack vector, low attack complexity, and no required privileges or user interaction (NVD, Wiz).
The vulnerability can allow context-dependent attackers to cause a denial of service through out-of-bounds read and crash conditions. Additionally, attackers may potentially read information from other memory locations when processing specially crafted DER-encoded data (Github Issue).
The primary mitigation is to upgrade CryptX to version 0.065 or later, which contains the fixed version of the tomcrypt library (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."