QID 198771

Date Published: 2022-05-05

QID 198771: Ubuntu Security Notification for Open Secure Sockets Layer (OpenSSL) Vulnerabilities (USN-5402-1)

Openssl incorrectly handled the c_rehashscript.
Openssl incorrectly verified certain responsesigning certificates.
Openssl used the incorrect mac key in therc4-md5 ciphersuite.
Openssl incorrectly handled resources whendecoding certificates and keys.

A local attacker could possibly use this issue to execute arbitrarycommands when c_rehash is run.
A remote attacker could possibly use this issue tospoof certain response signing certificates.
In non-default configurations were rc4-md5 is enabled,a remote attacker could possibly use this issue to modify encryptedcommunications.
A remote attacker could possibly use thisissue to cause openssl to consume resources, leading to a denial ofservice.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5402-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198771

    Software Advisories
    Advisory ID Software Component Link
    USN-5402-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5402-1