CVE-2022-37454

Source
https://cve.org/CVERecord?id=CVE-2022-37454
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37454.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-37454
Aliases
Downstream
Related
Published
2022-10-21T06:15:09.333Z
Modified
2026-02-08T04:13:20.142127Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

References

Affected packages

Git / github.com/php/php-src

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37454.json"

Git / github.com/python/cpython

Affected versions

v3.*
v3.10.0
v3.10.1
v3.10.2
v3.10.3
v3.10.4
v3.10.5
v3.10.6
v3.10.7
v3.10.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37454.json"