Skip to main content

CVE-2025-40913: CWE-1395 Dependency on Vulnerable Third-Party Component in ATRODO Net::Dropbear

Unknown
VulnerabilityCVE-2025-40913cvecve-2025-40913cwe-1395
Published: Wed Jul 16 2025 (07/16/2025, 14:05:33 UTC)
Source: CVE Database V5
Vendor/Project: ATRODO
Product: Net::Dropbear

Description

Net::Dropbear versions through 0.16 for Perl contains a dependency that may be susceptible to an integer overflow. Net::Dropbear embeds a version of the libtommath library that is susceptible to an integer overflow associated with CVE-2023-36328.

Technical Details

Data Version
5.1
Assigner Short Name
CPANSec
Date Reserved
2025-04-16T09:05:34.361Z
Cvss Version
null
State
PUBLISHED

Threat ID: 6877b42ca83201eaacdbbfdb

Added to database: 7/16/2025, 2:16:12 PM

Last updated: 7/16/2025, 2:16:12 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats