{"id":"BIT-python-min-2022-37454","details":"The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.","aliases":["BIT-libphp-2022-37454","BIT-libpython-2022-37454","BIT-php-2022-37454","BIT-php-min-2022-37454","BIT-python-2022-37454","CVE-2022-37454","GHSA-6w4m-2xhg-2658","PSF-2022-11","PYSEC-2026-504"],"modified":"2026-09-08T08:47:30.029865391Z","published":"2025-01-16T07:22:28.692Z","database_specific":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"severity":"Critical"},"references":[{"type":"ADVISORY","url":"https://csrc.nist.gov/projects/hash-functions/sha-3-project"},{"type":"WEB","url":"https://eprint.iacr.org/2023/331"},{"type":"ADVISORY","url":"https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/"},{"type":"ADVISORY","url":"https://mouha.be/sha-3-buffer-overflow/"},{"type":"ADVISORY","url":"https://news.ycombinator.com/item?id=33281106"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=35050307"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202305-02"},{"type":"ADVISORY","url":"https://www.debian.org/security/2022/dsa-5267"},{"type":"ADVISORY","url":"https://www.debian.org/security/2022/dsa-5269"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20230203-0001/"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-37454"}],"affected":[{"package":{"name":"python-min","ecosystem":"Bitnami","purl":"pkg:bitnami/python-min"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.6.0"},{"fixed":"3.7.16"},{"introduced":"3.8.0"},{"fixed":"3.8.16"},{"introduced":"3.9.0"},{"fixed":"3.9.16"},{"introduced":"3.10.0"},{"fixed":"3.10.9"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/python-min/BIT-python-min-2022-37454.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}],"schema_version":"1.9.0"}