MidnightBSD

Advisories for extended_keccak_code_package_project

CVE-2022-37454

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

Products Affected

Vendor Product Version
sha3_project sha3 *
pysha3_project pysha3 *
debian debian_linux 11.0
extended_keccak_code_package_project extended_keccak_code_package -
fedoraproject fedora 36
debian debian_linux 10.0
python python *
pypy pypy *
fedoraproject fedora 35
php php *