Vulnerability CVE-2022-37454: Information

Description

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

Severity: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Published: Oct. 21, 2022
Modified: May 3, 2023
Error type identifier: CWE-190

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
php7p107.4.33-alt17.4.33-alt1ALT-PU-2022-3024-1309489Fixed
php7p10_e2k7.4.33-alt17.4.33-alt1ALT-PU-2022-7016-1-Fixed
php7c10f17.4.33-alt17.4.33-alt1ALT-PU-2022-3024-1309489Fixed
php7c9f27.4.33-alt17.4.33-alt1ALT-PU-2022-3107-1309490Fixed
php7-curlp10_e2k7.4.33-alt17.4.33-alt1ALT-PU-2022-7017-1-Fixed
php7-gdp10_e2k7.4.33-alt17.4.33-alt1ALT-PU-2022-7018-1-Fixed
php7-intlp10_e2k7.4.33-alt17.4.33-alt1ALT-PU-2022-7024-1-Fixed
php7-opcachep10_e2k7.4.33-alt1.27.4.33-alt1.2ALT-PU-2022-7025-1-Fixed
php7-opensslp10_e2k7.4.33-alt17.4.33-alt1ALT-PU-2022-7019-1-Fixed
php7-pdo_mysqlp10_e2k7.4.33-alt17.4.33-alt1ALT-PU-2022-7020-1-Fixed
php7-pgsqlp10_e2k7.4.33-alt17.4.33-alt1ALT-PU-2022-7021-1-Fixed
php7-tidyp10_e2k7.4.33-alt17.4.33-alt1ALT-PU-2022-7027-1-Fixed
php7-xmlrpcp10_e2k7.4.33-alt17.4.33-alt1ALT-PU-2022-7026-1-Fixed
php7-xslp10_e2k7.4.33-alt1.17.4.33-alt1.1ALT-PU-2022-7023-1-Fixed
php7-zipp10_e2k7.4.33-alt17.4.33-alt1ALT-PU-2022-7022-1-Fixed
php8.0p108.0.25-alt18.0.30-alt1ALT-PU-2022-2986-1309328Fixed
php8.0p10_e2k8.0.25-alt18.0.30-alt1ALT-PU-2022-6881-1-Fixed
php8.0c10f18.0.25-alt18.0.30-alt1ALT-PU-2022-2986-1309328Fixed
php8.1sisyphus8.1.12-alt18.1.28-alt1ALT-PU-2022-2964-1309277Fixed
php8.1sisyphus_e2k8.1.12-alt18.1.28-alt1ALT-PU-2022-6838-1-Fixed
php8.1sisyphus_riscv648.1.12-alt18.1.28-alt1ALT-PU-2022-6857-1-Fixed
php8.1p108.1.12-alt18.1.28-alt1ALT-PU-2022-2988-1309327Fixed
php8.1p10_e2k8.1.12-alt18.1.28-alt1ALT-PU-2022-6882-1-Fixed
php8.1c10f18.1.12-alt18.1.28-alt1ALT-PU-2022-2988-1309327Fixed
php8.1c9f28.1.12-alt18.1.16-alt1ALT-PU-2022-3093-1309712Fixed
python3sisyphus3.11.0-alt13.12.2-alt1ALT-PU-2023-1951-1311250Fixed
python3sisyphus_e2k3.11.4-alt13.12.2-alt1ALT-PU-2023-3859-1-Fixed
python3sisyphus_riscv643.11.0-alt13.12.2-alt1ALT-PU-2023-3923-1-Fixed
python3p103.9.16-alt13.9.18-alt1ALT-PU-2023-1518-1317117Fixed
python3p10_e2k3.9.16-alt13.9.18-alt1ALT-PU-2023-3007-1-Fixed
python3p93.7.17-alt13.7.17-alt1ALT-PU-2024-2598-2340935Fixed
python3c10f13.9.16-alt13.9.18-alt0.c10f1.1ALT-PU-2023-1518-1317117Fixed
python3c9f23.7.17-alt13.7.17-alt1ALT-PU-2024-3474-2342077Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:extended_keccak_code_package_project:extended_keccak_code_package:-:*:*:*:*:*:*:*

      Configuration 2

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
      Start including
      7.2.0
      End excliding
      7.4.33

      cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
      Start including
      8.1.0
      End excliding
      8.1.12

      cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
      Start including
      8.0.0
      End excliding
      8.0.25

      Configuration 5

      cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
      Start including
      3.6.0
      End excliding
      3.7.16

      cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
      Start including
      3.10.0
      End excliding
      3.10.9

      cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
      Start including
      3.9.0
      End excliding
      3.9.16

      cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
      Start including
      3.8.0
      End excliding
      3.8.16

      Configuration 6

      cpe:2.3:a:sha3_project:sha3:*:*:*:*:*:ruby:*:*
      End excliding
      1.0.5

      Configuration 7

      cpe:2.3:a:pysha3_project:pysha3:*:*:*:*:*:*:*:*

      Configuration 8

      cpe:2.3:a:pypy:pypy:*:*:*:*:*:*:*:*
      Start including
      7.0.0