CVE-2024-58040: Crypt::RandomEncryption for Perl uses insecure rand() function during encryption
Published Sep 29, 2025
·Updated
Crypt::RandomEncryption for Perl version 0.01 uses insecure rand() function during encryption.
Affected Software
2 affected components
Perl Crypt::RandomEncryption
Qwer Crypt\=\-randomencryption
Event History
Sep 29, 2025
CVE Published
via MITRE·11:54 PM
Data Sourced
via MITRE·11:54 PM
DescriptionWeakness
Sep 30, 2025
Data Sourced
via NVD·11:37 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-58040?
CVE-2024-58040 is considered a high severity vulnerability due to its use of insecure random number generation in encryption.
2
How do I fix CVE-2024-58040?
To fix CVE-2024-58040, upgrade to a version of Crypt::RandomEncryption that does not use the insecure rand() function for encryption.
3
What systems are affected by CVE-2024-58040?
CVE-2024-58040 specifically affects users of Perl Crypt::RandomEncryption version 0.01.
4
What type of vulnerability is CVE-2024-58040?
CVE-2024-58040 is a cryptographic vulnerability due to inadequate random number generation.
5
What are the potential impacts of CVE-2024-58040?
The potential impacts of CVE-2024-58040 include increased risk of encryption being compromised, leading to unauthorized data access.