CVE-2025-15638: Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt
Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt.
Net::Dropbear versions before 0.14 includes versions of Dropbear 2019.78 or earlier. These include versions of libtomcrypt v1.18.1 or earlier, which is affected by CVE-2016-6129 and CVE-2018-12437.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15638?
CVE-2025-15638 is classified as a high-severity vulnerability due to its potential to compromise cryptographic operations.
How do I fix CVE-2025-15638?
To fix CVE-2025-15638, upgrade Net::Dropbear to version 0.14 or later.
Which versions are affected by CVE-2025-15638?
CVE-2025-15638 affects Net::Dropbear versions before 0.14 and Dropbear versions 2019.78 or earlier.
What component is vulnerable in CVE-2025-15638?
CVE-2025-15638 involves a vulnerable version of libtomcrypt included in Net::Dropbear before version 0.14.
Is there a workaround for CVE-2025-15638?
There is no known effective workaround for CVE-2025-15638 other than upgrading to a secure version.