Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-37454


The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.


Published

2022-10-21T06:15:09.333

Last Modified

2025-05-08T15:15:47.043

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-190
  • Type: Secondary
    CWE-190

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application extended_keccak_code_package_project extended_keccak_code_package - Yes
Operating System debian debian_linux 10.0 Yes
Operating System debian debian_linux 11.0 Yes
Operating System fedoraproject fedora 35 Yes
Operating System fedoraproject fedora 36 Yes
Application php php < 7.4.33 Yes
Application php php < 8.0.25 Yes
Application php php < 8.1.12 Yes
Application python python < 3.7.16 Yes
Application python python < 3.8.16 Yes
Application python python < 3.9.16 Yes
Application python python < 3.10.9 Yes
Application sha3_project sha3 < 1.0.5 Yes
Application pysha3_project pysha3 * Yes
Application pypy pypy ≥ 7.0.0 Yes

References