CVE-2022-1292
Published: 3 May 2022
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).
Priority
Status
Package | Release | Status |
---|---|---|
edk2 Launchpad, Ubuntu, Debian |
kinetic |
Not vulnerable
|
lunar |
Not vulnerable
|
|
upstream |
Needs triage
|
|
trusty |
Does not exist
|
|
bionic |
Not vulnerable
|
|
focal |
Not vulnerable
|
|
impish |
Not vulnerable
|
|
jammy |
Not vulnerable
|
|
xenial |
Needs triage
|
|
nodejs Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(uses system openssl1.0)
|
focal |
Not vulnerable
(uses system openssl1.1)
|
|
impish |
Not vulnerable
(uses system openssl1.1)
|
|
kinetic |
Not vulnerable
(uses system openssl1.1)
|
|
lunar |
Not vulnerable
(uses system openssl1.1)
|
|
trusty |
Not vulnerable
(uses system openssl)
|
|
upstream |
Needs triage
|
|
xenial |
Not vulnerable
(uses system openssl)
|
|
jammy |
Needed
|
|
openssl Launchpad, Ubuntu, Debian |
kinetic |
Released
(3.0.2-0ubuntu2)
|
lunar |
Released
(3.0.2-0ubuntu2)
|
|
upstream |
Released
(1.1.1o,3.0.3)
|
|
bionic |
Released
(1.1.1-1ubuntu2.1~18.04.17)
|
|
focal |
Released
(1.1.1f-1ubuntu2.13)
|
|
impish |
Released
(1.1.1l-1ubuntu1.3)
|
|
jammy |
Released
(3.0.2-0ubuntu1.1)
|
|
Patches: upstream: https://git.openssl.org/?p=openssl.git;a=commit;h=e5fd1728ef4c7a5bf7c7a7163ca60370460a6e23 (1.1) upstream: https://git.openssl.org/?p=openssl.git;a=commit;h=1ad73b4d27bd8c1b369a3cd453681d3a4f1bb9b2 (3.0) |
||
openssl1.0 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
kinetic |
Does not exist
|
|
lunar |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Does not exist
|
|
bionic |
Released
(1.0.2n-1ubuntu5.9)
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 9.8 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |