CVE-2022-1292
Summary
| CVE | CVE-2022-1292 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-03 16:15:00 UTC |
| Updated | 2023-11-07 03:41:00 UTC |
| Description | The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd). |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 35 | All | All | All |
| Operating System | Fedoraproject | Fedora | 36 | All | All | All |
| Hardware | Netapp | A250 | - | All | All | All |
| Operating System | Netapp | A250 Firmware | - | All | All | All |
| Hardware | Netapp | A700s | - | All | All | All |
| Operating System | Netapp | A700s Firmware | - | All | All | All |
| Application | Netapp | Active Iq Unified Manager | - | All | All | All |
| Application | Netapp | Active Iq Unified Manager | - | All | All | All |
| Application | Netapp | Active Iq Unified Manager | - | All | All | All |
| Hardware | Netapp | Aff 500f | - | All | All | All |
| Operating System | Netapp | Aff 500f Firmware | - | All | All | All |
| Hardware | Netapp | Aff 8300 | - | All | All | All |
| Operating System | Netapp | Aff 8300 Firmware | - | All | All | All |
| Hardware | Netapp | Aff 8700 | - | All | All | All |
| Operating System | Netapp | Aff 8700 Firmware | - | All | All | All |
| Hardware | Netapp | Aff A400 | - | All | All | All |
| Operating System | Netapp | Aff A400 Firmware | - | All | All | All |
| Application | Netapp | Clustered Data Ontap | - | All | All | All |
| Application | Netapp | Clustered Data Ontap Antivirus Connector | - | All | All | All |
| Hardware | Netapp | Fabric-attached Storage A400 | - | All | All | All |
| Operating System | Netapp | Fabric-attached Storage A400 Firmware | - | All | All | All |
| Hardware | Netapp | Fas 500f | - | All | All | All |
| Operating System | Netapp | Fas 500f Firmware | - | All | All | All |
| Hardware | Netapp | Fas 8300 | - | All | All | All |
| Operating System | Netapp | Fas 8300 Firmware | - | All | All | All |
| Hardware | Netapp | Fas 8700 | - | All | All | All |
| Operating System | Netapp | Fas 8700 Firmware | - | All | All | All |
| Hardware | Netapp | H300e | - | All | All | All |
| Operating System | Netapp | H300e Firmware | - | All | All | All |
| Hardware | Netapp | H300s | - | All | All | All |
| Operating System | Netapp | H300s Firmware | - | All | All | All |
| Hardware | Netapp | H410s | - | All | All | All |
| Operating System | Netapp | H410s Firmware | - | All | All | All |
| Hardware | Netapp | H500e | - | All | All | All |
| Operating System | Netapp | H500e Firmware | - | All | All | All |
| Hardware | Netapp | H500s | - | All | All | All |
| Operating System | Netapp | H500s Firmware | - | All | All | All |
| Hardware | Netapp | H700e | - | All | All | All |
| Operating System | Netapp | H700e Firmware | - | All | All | All |
| Hardware | Netapp | H700s | - | All | All | All |
| Operating System | Netapp | H700s Firmware | - | All | All | All |
| Application | Netapp | Oncommand Insight | - | All | All | All |
| Application | Netapp | Oncommand Workflow Automation | - | All | All | All |
| Application | Netapp | Santricity Smi-s Provider | - | All | All | All |
| Application | Netapp | Smi-s Provider | - | All | All | All |
| Application | Netapp | Snapcenter | - | All | All | All |
| Application | Netapp | Snapmanager | - | All | All | All |
| Application | Netapp | Solidfire Enterprise Sds Hci Storage Node | - | All | All | All |
| Application | Netapp | Solidfire Hci Management Node | - | All | All | All |
| Application | Openssl | Openssl | All | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.4.0.0 | All | All | All |
| Application | Oracle | Mysql Server | All | All | All | All |
| Application | Oracle | Mysql Server | All | All | All | All |
| Application | Oracle | Mysql Workbench | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 36 Update: openssl1.1-1.1.1o-1.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| July 2022 MySQL Server Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| OpenSSL: Multiple Vulnerabilities (GLSA 202210-02) — Gentoo security | GENTOO | security.gentoo.org | |
| Debian -- Security Information -- DSA-5139-1 openssl | DEBIAN | www.debian.org | |
| [SECURITY] Fedora 35 Update: openssl-1.1.1o-1.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| git.openssl.org Git - openssl.git/commitdiff | git.openssl.org | ||
| git.openssl.org Git | git.openssl.org | ||
| cert-portal.siemens.com/productcert/pdf/ssa-953464.pdf | MISC | cert-portal.siemens.com | |
| [SECURITY] Fedora 36 Update: openssl1.1-1.1.1o-1.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| May 2022 OpenSSL Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| [SECURITY] [DLA 3008-1] openssl security update | MLIST | lists.debian.org | |
| [SECURITY] Fedora 35 Update: openssl-1.1.1o-1.fc35 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| git.openssl.org Git - openssl.git/commitdiff | CONFIRM | git.openssl.org | |
| git.openssl.org Git - openssl.git/commitdiff | CONFIRM | git.openssl.org | |
| www.openssl.org/news/secadv/20220503.txt | CONFIRM | www.openssl.org | |
| Security Advisory | CONFIRM | psirt.global.sonicwall.com | |
| Oracle Critical Patch Update Advisory - July 2022 | N/A | www.oracle.com | |
| git.openssl.org Git - openssl.git/commitdiff | git.openssl.org | ||
| git.openssl.org Git - openssl.git/commitdiff | CONFIRM | git.openssl.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Elison Niven (Sophos)
Legacy QID Mappings
- 160014 Oracle Enterprise Linux Security Update for Open Secure Sockets Layer (OpenSSL) (ELSA-2022-5818)
- 160025 Oracle Enterprise Linux Security Update for Open Secure Sockets Layer (OpenSSL) (ELSA-2022-9683)
- 160072 Oracle Enterprise Linux Security Update for Open Secure Sockets Layer (OpenSSL) (ELSA-2022-6224)
- 179286 Debian Security Update for Open Secure Sockets Layer (OpenSSL) (DLA 3008-1)
- 179294 Debian Security Update for Open Secure Sockets Layer (OpenSSL) (DSA 5139-1)
- 183232 Debian Security Update for Open Secure Sockets Layer (OpenSSL) (CVE-2022-1292)
- 198771 Ubuntu Security Notification for Open Secure Sockets Layer (OpenSSL) Vulnerabilities (USN-5402-1)
- 199873 Ubuntu Security Notification for Node.js Vulnerabilities (USN-6457-1)
- 20266 Oracle MySQL July 2022 Critical Patch Update (CPUJUL2022)
- 240588 Red Hat Update for Open Secure Sockets Layer (OpenSSL) (RHSA-2022:5818)
- 240641 Red Hat Update for Open Secure Sockets Layer (OpenSSL) (RHSA-2022:6224)
- 240996 Red Hat Update for JBoss Core Services (RHSA-2022:8840)
- 242229 Red Hat Update for Satellite 6.11.5.6 (RHSA-2023:5980)
- 242230 Red Hat Update for Satellite 6.12.5.2 (RHSA-2023:5979)
- 242347 Red Hat Update for Satellite 6.14 (RHSA-2023:6818)
- 242363 Red Hat Update for Satellite 6.13.5 (RHSA-2023:5931)
- 282860 Fedora Security Update for openssl1.1 (FEDORA-2022-b651cb69e6)
- 282873 Fedora Security Update for Open Secure Sockets Layer (OpenSSL) (FEDORA-2022-c9c02865f6)
- 296082 Oracle Solaris 11.4 Support Repository Update (SRU) 48.126.1 Missing (CPUJUL2022)
- 296085 Oracle Solaris 11.3 Support Repository Update (SRU) 36.30.0 Missing (CPUOCT2022)
- 330109 IBM Advanced Interactive eXecutive (AIX) Open Secure Sockets Layer (OpenSSL) Arbritary Code Execution Vulnerability (openssl_advisory36)
- 353941 Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL) : ALAS2-2022-1801
- 353970 Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL) : ALAS-2022-1605
- 353983 Amazon Linux Security Advisory for openssl11 : ALAS2-2022-1815
- 354355 Amazon Linux Security Advisory for Open Secure Sockets Layer1.1 (OpenSSL1.1) : ALAS2022-2022-105
- 354511 Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL) : ALAS2022-2022-104
- 354636 Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL) : AL2012-2022-368
- 355250 Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL) : ALAS2023-2023-051
- 357333 Amazon Linux Security Advisory for edk2 : ALAS2-2024-2502
- 377563 Alibaba Cloud Linux Security Update for Open Secure Sockets Layer (OpenSSL) (ALINUX3-SA-2022:0148)
- 501987 Alpine Linux Security Update for Open Secure Sockets Layer3 (OpenSSL3)
- 591170 Mitsubishi Electric GT SoftGOT2000 Multiple Vulnerabilities (ICSA-22-221-01)
- 591184 Mitsubishi Electric Multiple Factory Automation Products (Update C) Multiple Vulnerabilities (ICSA-22-221-01)
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 671852 EulerOS Security Update for Open Secure Sockets Layer (OpenSSL) (EulerOS-SA-2022-1909)
- 671890 EulerOS Security Update for Open Secure Sockets Layer (OpenSSL) (EulerOS-SA-2022-1943)
- 671896 EulerOS Security Update for compat-openssl10 (EulerOS-SA-2022-1924)
- 671917 EulerOS Security Update for Open Secure Sockets Layer (OpenSSL) (EulerOS-SA-2022-2007)
- 671930 EulerOS Security Update for Open Secure Sockets Layer (OpenSSL) (EulerOS-SA-2022-1977)
- 671989 EulerOS Security Update for Open Secure Sockets Layer (OpenSSL) (EulerOS-SA-2022-2143)
- 672004 EulerOS Security Update for Open Secure Sockets Layer (OpenSSL) (EulerOS-SA-2022-2168)
- 672251 EulerOS Security Update for Open Secure Sockets Layer (OpenSSL) (EulerOS-SA-2022-2629)
- 672447 EulerOS Security Update for linux-sgx (EulerOS-SA-2022-2852)
- 673086 EulerOS Security Update for Open Secure Sockets Layer (OpenSSL)111d (EulerOS-SA-2023-2162)
- 690862 Free Berkeley Software Distribution (FreeBSD) Security Update for Open Secure Sockets Layer (OpenSSL) (fceb2b08-cb76-11ec-a06f-d4c9ef517024)
- 690902 Free Berkeley Software Distribution (FreeBSD) Security Update for mysql (8e150606-08c9-11ed-856e-d4c9ef517024)
- 710638 Gentoo Linux Open Secure Sockets Layer (OpenSSL) Multiple Vulnerabilities (GLSA 202210-02)
- 752230 SUSE Enterprise Linux Security Update for openssl-1_1 (SUSE-SU-2022:2075-1)
- 752236 SUSE Enterprise Linux Security Update for openssl-1_1 (SUSE-SU-2022:2068-1)
- 752241 SUSE Enterprise Linux Security Update for openssl-1_0_0 (SUSE-SU-2022:2106-1)
- 752249 SUSE Enterprise Linux Security Update for Open Secure Sockets Layer (OpenSSL) (SUSE-SU-2022:2098-1)
- 752273 SUSE Enterprise Linux Security Update for openssl-1_1 (SUSE-SU-2022:2182-1)
- 752280 SUSE Enterprise Linux Security Update for openssl-1_0_0 (SUSE-SU-2022:2197-1)
- 752283 SUSE Enterprise Linux Security Update for openssl-1_1 (SUSE-SU-2022:2251-1)
- 752298 SUSE Enterprise Linux Security Update for openssl-1_1 (SUSE-SU-2022:2308-1)
- 752308 SUSE Enterprise Linux Security Update for openssl-3 (SUSE-SU-2022:2306-1)
- 752323 SUSE Enterprise Linux Security Update for openssl-1_0_0 (SUSE-SU-2022:2321-1)
- 901302 Common Base Linux Mariner (CBL-Mariner) Security Update for Open Secure Sockets Layer (OpenSSL) (9654)
- 901542 Common Base Linux Mariner (CBL-Mariner) Security Update for Open Secure Sockets Layer (OpenSSL) (9649)
- 902028 Common Base Linux Mariner (CBL-Mariner) Security Update for Open Secure Sockets Layer (OpenSSL) (9654-1)
- 902132 Common Base Linux Mariner (CBL-Mariner) Security Update for Open Secure Sockets Layer (OpenSSL) (9649-1)
- 904875 Common Base Linux Mariner (CBL-Mariner) Security Update for rust (12429)
- 904960 Common Base Linux Mariner (CBL-Mariner) Security Update for cloud-hypervisor (12303)
- 905020 Common Base Linux Mariner (CBL-Mariner) Security Update for rust (12640)
- 940611 AlmaLinux Security Update for Open Secure Sockets Layer (OpenSSL) (ALSA-2022:5818)
- 940649 AlmaLinux Security Update for Open Secure Sockets Layer (OpenSSL) (ALSA-2022:6224)
- 960214 Rocky Linux Security Update for Open Secure Sockets Layer (OpenSSL) (RLSA-2022:5818)
- 961065 Rocky Linux Security Update for Satellite (RLSA-2023:6818)