cbcvebase.
CVE-2022-37454
published 2022-10-21

CVE-2022-37454: The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary…

PriorityP358critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.19%
91.5th percentile
The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianphp7.4< php7.4 7.4.33-1+deb11u1 (bullseye)php7.4 7.4.33-1+deb11u1 (bullseye)
debianpypy3< php7.4 7.4.33-1+deb11u1 (bullseye)php7.4 7.4.33-1+deb11u1 (bullseye)
debianpysha3< php7.4 7.4.33-1+deb11u1 (bullseye)php7.4 7.4.33-1+deb11u1 (bullseye)
debianpython2.7< php7.4 7.4.33-1+deb11u1 (bullseye)php7.4 7.4.33-1+deb11u1 (bullseye)
debianpython3.9< php7.4 7.4.33-1+deb11u1 (bullseye)php7.4 7.4.33-1+deb11u1 (bullseye)
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_php_8.1.12-1_on_cbl_mariner_2.0
msrccbl2_python3_3.9.14-5_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_python3_3.7.13-5_on_cbl_mariner_1.0
paloaltopan-os
phpphp>= 7.2.0 < 7.4.337.4.33
phpphp>= 8.0.0 < 8.0.258.0.25
phpphp>= 8.1.0 < 8.1.128.1.12
pypypypy>= 7.0.0
pythonpython>= 3.10.0 < 3.10.93.10.9
pythonpython>= 3.6.0 < 3.7.163.7.16
pythonpython>= 3.8.0 < 3.8.163.8.16
pythonpython>= 3.9.0 < 3.9.163.9.16

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.