Wind River Support Network

HomeDefectsLIN1021-4618
Fixed

LIN1021-4618 : Security Advisory - python - CVE-2022-37454

Created: Oct 21, 2022    Updated: Mar 1, 2023
Resolved Date: Mar 1, 2023
Found In Version: 10.21.20.1
Fix Version: 10.21.20.17
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

https://github.com/python/cpython/issues/98517

CREATE(Triage):(User=admin) CVE-2022-37454 (https://nvd.nist.gov/vuln/detail/CVE-2022-37454)

CVEs


Live chat
Online