QID 354639

Date Published: 2023-01-02

QID 354639: Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL) : AL2012-2022-371

Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2022-2068:
A flaw was found in OpenSSL. The issue in CVE-2022-1292 did not find other places in the `c_rehash` script where it possibly passed the file names of certificates being hashed to a command executed through the shell. Some operating systems distribute this script in a manner where it is automatically executed. On these operating systems, this flaw allows an attacker to execute arbitrary commands with the privileges of the script. 2097310: CVE-2022-2068 openssl: the c_rehash script allows command injection

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Administrators are advised to apply the appropriate software updates.
    Vendor References

    CVEs related to QID 354639

    Software Advisories
    Advisory ID Software Component Link
    AL2012-2022-371 Amazon Linux Bare Metal URL Logo docs.aws.amazon.com/AWSEC2/latest/UserGuide/install-updates.html