The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
Configuration 2 (hide)
            
            
  | 
    
Configuration 3 (hide)
            
            
  | 
    
Configuration 4 (hide)
            
            
  | 
    
Configuration 5 (hide)
            
            
  | 
    
Configuration 6 (hide)
            
            
  | 
    
Configuration 7 (hide)
            
            
  | 
    
Configuration 8 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2022-10-21 06:15
Updated : 2023-05-03 11:15
NVD link : CVE-2022-37454
Mitre link : CVE-2022-37454
CVE.ORG link : CVE-2022-37454
JSON object : View
Products Affected
                python
- python
 
fedoraproject
- fedora
 
pysha3_project
- pysha3
 
extended_keccak_code_package_project
- extended_keccak_code_package
 
pypy
- pypy
 
debian
- debian_linux
 
php
- php
 
sha3_project
- sha3
 
CWE
                
                    
                        
                        CWE-190
                        
            Integer Overflow or Wraparound
