[ALAS2-2022-1815] Amazon Linux 2 2017.12 - ALAS2-2022-1815: medium priority package update for openssl11
Severity
Medium
Affected Packages
15
CVEs
1
Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2022-1292:
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).
- ID
- ALAS2-2022-1815
- Severity
- medium
- URL
- https://alas.aws.amazon.com/AL2/ALAS-2022-1815.html
- Published
-
2022-07-06T03:14:00
(2 years ago) - Modified
-
2022-07-14T22:22:00
(2 years ago) - Rights
- Amazon Linux Security Team
- Other Advisories
-
- ALAS-2022-1605
- ALAS2-2022-1801
- ALAS2-2024-2502
- ALSA-2022:5818
- ALSA-2022:6224
- DSA-5139-1
- ELSA-2022-5818
- ELSA-2022-6224
- ELSA-2022-9683
- ELSA-2022-9751
- FEDORA-2022-b651cb69e6
- FEDORA-2022-c9c02865f6
- FREEBSD:8E150606-08C9-11ED-856E-D4C9EF517024
- FREEBSD:FCEB2B08-CB76-11EC-A06F-D4C9EF517024
- GLSA-202210-02
- MS:CVE-2022-1292
- RHSA-2022:5818
- RHSA-2022:6224
- RLSA-2022:5818
- SECADV-20220503-1
- SSA:2022-124-02
- SSA:2022-174-01
- SSA:2022-179-03
- SUSE-SU-2022:2068-1
- SUSE-SU-2022:2075-1
- SUSE-SU-2022:2098-1
- SUSE-SU-2022:2106-1
- SUSE-SU-2022:2182-1
- SUSE-SU-2022:2197-1
- SUSE-SU-2022:2251-1
- SUSE-SU-2022:2251-2
- SUSE-SU-2022:2306-1
- SUSE-SU-2022:2308-1
- SUSE-SU-2022:2321-1
- USN-5402-1
- USN-5402-2
- USN-6457-1
- USN-7018-1
Source | # ID | Name | URL |
---|---|---|---|
CVE | CVE-2022-1292 | http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1292 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/amazonlinux/openssl11?arch=x86_64&distro=amazonlinux-2 | amazonlinux | openssl11 | < 1.1.1g-12.amzn2.0.8 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/openssl11?arch=i686&distro=amazonlinux-2 | amazonlinux | openssl11 | < 1.1.1g-12.amzn2.0.8 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/openssl11?arch=aarch64&distro=amazonlinux-2 | amazonlinux | openssl11 | < 1.1.1g-12.amzn2.0.8 | amazonlinux-2 | aarch64 | |
Affected | pkg:rpm/amazonlinux/openssl11-static?arch=x86_64&distro=amazonlinux-2 | amazonlinux | openssl11-static | < 1.1.1g-12.amzn2.0.8 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/openssl11-static?arch=i686&distro=amazonlinux-2 | amazonlinux | openssl11-static | < 1.1.1g-12.amzn2.0.8 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/openssl11-static?arch=aarch64&distro=amazonlinux-2 | amazonlinux | openssl11-static | < 1.1.1g-12.amzn2.0.8 | amazonlinux-2 | aarch64 | |
Affected | pkg:rpm/amazonlinux/openssl11-libs?arch=x86_64&distro=amazonlinux-2 | amazonlinux | openssl11-libs | < 1.1.1g-12.amzn2.0.8 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/openssl11-libs?arch=i686&distro=amazonlinux-2 | amazonlinux | openssl11-libs | < 1.1.1g-12.amzn2.0.8 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/openssl11-libs?arch=aarch64&distro=amazonlinux-2 | amazonlinux | openssl11-libs | < 1.1.1g-12.amzn2.0.8 | amazonlinux-2 | aarch64 | |
Affected | pkg:rpm/amazonlinux/openssl11-devel?arch=x86_64&distro=amazonlinux-2 | amazonlinux | openssl11-devel | < 1.1.1g-12.amzn2.0.8 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/openssl11-devel?arch=i686&distro=amazonlinux-2 | amazonlinux | openssl11-devel | < 1.1.1g-12.amzn2.0.8 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/openssl11-devel?arch=aarch64&distro=amazonlinux-2 | amazonlinux | openssl11-devel | < 1.1.1g-12.amzn2.0.8 | amazonlinux-2 | aarch64 | |
Affected | pkg:rpm/amazonlinux/openssl11-debuginfo?arch=x86_64&distro=amazonlinux-2 | amazonlinux | openssl11-debuginfo | < 1.1.1g-12.amzn2.0.8 | amazonlinux-2 | x86_64 | |
Affected | pkg:rpm/amazonlinux/openssl11-debuginfo?arch=i686&distro=amazonlinux-2 | amazonlinux | openssl11-debuginfo | < 1.1.1g-12.amzn2.0.8 | amazonlinux-2 | i686 | |
Affected | pkg:rpm/amazonlinux/openssl11-debuginfo?arch=aarch64&distro=amazonlinux-2 | amazonlinux | openssl11-debuginfo | < 1.1.1g-12.amzn2.0.8 | amazonlinux-2 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |