Wind River Support Network

HomeDefectsLIN1018-9918
Fixed

LIN1018-9918 : Security Advisory - python - CVE-2022-37454

Created: Oct 21, 2022    Updated: Feb 24, 2023
Resolved Date: Feb 24, 2023
Found In Version: 10.18.44.1
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

https://github.com/python/cpython/issues/98517

CREATE(Triage):(User=admin) CVE-2022-37454 (https://nvd.nist.gov/vuln/detail/CVE-2022-37454)
Live chat
Online