MidnightBSD

Advisories for pysha3_project

CVE-2022-37454

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

Products Affected

Vendor Product Version
pypy pypy *
sha3_project sha3 *
debian debian_linux 10.0
debian debian_linux 11.0
pysha3_project pysha3 *
extended_keccak_code_package_project extended_keccak_code_package -
fedoraproject fedora 35
php php *
python python *
fedoraproject fedora 36