The P5 Crypt Perl Project maintains a cryptographic library embedded in Perl environments, where despite a narrow product footprint the library's placement in the software supply chain can amplify the reach of any flaw across downstream applications and systems that depend on it. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by P5 Crypt Perl Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13895HIGH Crypt::Perl::ECDSA in the Crypt::Perl (aka p5-Crypt-Perl) module before 0.32 for Perl fails to verify correct ECDSA signatures when r and s are small and when s = 1. This happens w | Jun 7, 2020 | 8.8 | 28 | NO | NO |
CVE-2020-17478HIGH ECDSA/EC/Point.pm in Crypt::Perl before 0.33 does not properly consider timing attacks against the EC point multiplication algorithm. | Aug 10, 2020 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by P5 Crypt Perl Project.
Media articles that mention a CVE ID that affects a product developed by P5 Crypt Perl Project — matched by CVE ID, not by vendor name.