libtom libtommath
cpe:2.3:a:libtom:libtommath:*:*:*:*:*:*:*
- < commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9
A critical integer overflow vulnerability has been identified in Perl CryptX versions prior to 0.087. This issue arises from CryptX embedding a vulnerable version of the LibTomMath library, which is susceptible to an integer overflow in the 'mp_grow' function. The overflow can be exploited by attackers to execute arbitrary code and cause a denial-of-service condition.
Exploitation of this vulnerability allows for arbitrary code execution and the introduction of a denial-of-service condition.
The vulnerability can be reproduced by using a version of Perl CryptX prior to 0.087 that includes the vulnerable LibTomMath library. The 'mp_grow' function can be called with a negative size argument, which triggers the integer overflow.
Users can upgrade to Perl CryptX version 0.087 or later, which addresses this vulnerability by including a patched version of the LibTomMath library. Instructions for upgrading can be found in the Perl CryptX documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.