CVE-2022-37454

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:extended_keccak_code_package_project:extended_keccak_code_package:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

Configuration 6 (hide)

cpe:2.3:a:sha3_project:sha3:*:*:*:*:*:ruby:*:*

Configuration 7 (hide)

cpe:2.3:a:pysha3_project:pysha3:*:*:*:*:*:*:*:*

Configuration 8 (hide)

cpe:2.3:a:pypy:pypy:*:*:*:*:*:*:*:*

Information

Published : 2022-10-20 23:15

Updated : 2023-03-06 20:15


NVD link : CVE-2022-37454

Mitre link : CVE-2022-37454


JSON object : View

CWE
CWE-190

Integer Overflow or Wraparound

Advertisement

dedicated server usa

Products Affected

sha3_project

  • sha3

python

  • python

extended_keccak_code_package_project

  • extended_keccak_code_package

pysha3_project

  • pysha3

pypy

  • pypy

fedoraproject

  • fedora

php

  • php

debian

  • debian_linux