• Tenable
  • CVEs
  • Settings
    Links
    Tenable.io Tenable Community & Support Tenable University
    Severity
    Theme
  • Tenable
  • Links
  • Tenable.io
  • Tenable Community & Support
  • Tenable University
  • Settings
  • Severity
  • Theme
  • Newest
  • Updated
  • Search
  • Newest
  • Updated
  • Search
  1. CVEs
  2. CVE-2022-37454
  1. CVEs

CVE-2022-37454

critical
  • Information
  • CPEs
  • Plugins

Description

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

References

https://news.ycombinator.com/item?id=33281106

https://csrc.nist.gov/projects/hash-functions/sha-3-project

https://mouha.be/sha-3-buffer-overflow/

https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658

https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html

https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html

https://www.debian.org/security/2022/dsa-5267

https://www.debian.org/security/2022/dsa-5269

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/

https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/

https://eprint.iacr.org/2023/331

https://news.ycombinator.com/item?id=35050307

Details

Source: MITRE

Published: 2022-10-21

Updated: 2023-03-07

Type: CWE-190

  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2023 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance