PT-2022-3301 · Openssl+10 · Openssl+10

Chancen

·

Published

2022-06-21

·

Updated

2026-04-27

·

CVE-2022-2068

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenSSL versions 3.0.0 through 3.0.3 OpenSSL versions 1.1.1 through 1.1.1o OpenSSL versions 1.0.2 through 1.0.2ze
Description The issue is related to improper encryption and potential buffer overflow, allowing a remote attacker to obtain sensitive information or execute arbitrary code. This can be achieved by sending specially crafted requests, potentially during the establishment of a TLS connection. The c rehash script is also affected, allowing command injection due to improper sanitization of shell metacharacters.
Recommendations For OpenSSL versions 3.0.0 through 3.0.3, update to version 3.0.4 to resolve the issue. For OpenSSL versions 1.1.1 through 1.1.1o, update to version 1.1.1p to resolve the issue. For OpenSSL versions 1.0.2 through 1.0.2ze, update to version 1.0.2zf to resolve the issue. As a temporary workaround, consider replacing the use of the c rehash script with the OpenSSL rehash command line tool to minimize the risk of command injection.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:5818
ALSA-2022:6224
ALT-PU-2022-2132
ALT-PU-2022-2139
ALT-PU-2022-2173
ALT-PU-2022-2184
ALT-PU-2022-3072
ALT-PU-2023-1299
AZL-9967
BDU:2022-04039
CESA-2022_5818
CVE-2022-2068
DSA-5169-1
JLSEC-2026-229
MGASA-2022-0246
OESA-2022-1737
OESA-2022-1898
OESA-2022-1899
OPENSUSE-SU-2022_2251-1
OPENSUSE-SU-2022_2306-1
OPENSUSE-SU-2022_2308-1
OPENSUSE-SU-2022_2321-1
OPENSUSE-SU-2024:12159-1
OPENSUSE-SU-2024:12178-1
OPENSUSE-SU-2025:15136-1
RHSA-2022:5818
RHSA-2022:6224
RHSA-2022:8840
RHSA-2022:8917
RHSA-2022_5818
RHSA-2022_6224
RHSA-2023:5931
RHSA-2023:5979
RHSA-2023:5980
RHSA-2023:5982
RHSA-2023:6818
RLSA-2022:5818
RLSA-2023:6818
SUSE-SU-2022:2179-1
SUSE-SU-2022:2180-1
SUSE-SU-2022:2181-1
SUSE-SU-2022:2182-1
SUSE-SU-2022:2197-1
SUSE-SU-2022:2251-1
SUSE-SU-2022:2251-2
SUSE-SU-2022:2306-1
SUSE-SU-2022:2308-1
SUSE-SU-2022:2309-1
SUSE-SU-2022:2321-1
SUSE-SU-2022_2179-1
SUSE-SU-2022_2180-1
SUSE-SU-2022_2181-1
SUSE-SU-2022_2309-1
USN-5488-1
USN-5488-2
USN-6457-1
USN-7018-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Ibm Aix
Linuxmint
Openssl
Red Hat
Rocky Linux
Suse
Ubuntu