ZeroHour

CVE-2022-37454

PoC
CVSS 3.1
9.8 critical
EPSS
6%p93
Published
()
Modified
Description

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

Vendors
extended keccak code package projectdebianfedoraprojectphppythonsha3 projectpysha3 projectpypy
Products
extended keccak code package, debian linux, fedora, php, python, sha3, pysha3, pypy
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.