[SECADV-20220621-1] The c_rehash script allows command injection

Severity Moderate
Affected Packages 51
Fixed Packages 3
CVEs 1

Command injection

In addition to the c_rehash shell command injection identified in
CVE-2022-1292, further circumstances where the c_rehash script does not
properly sanitise shell metacharacters to prevent command injection were
found by code review.

When the CVE-2022-1292 was fixed it was not discovered that there
are other places in the script where the file names of certificates
being hashed were possibly passed to a command executed through the shell.

This script is distributed by some operating systems in a manner where
it is automatically executed. On such operating systems, an attacker
could execute arbitrary commands with the privileges of the script.

Use of the c_rehash script is considered obsolete and should be replaced
by the OpenSSL rehash command line tool.

Package Affected Version
pkg:openssl/openssl = 3.0.0
pkg:openssl/openssl = 3.0.1
pkg:openssl/openssl = 3.0.2
pkg:openssl/openssl = 3.0.3
pkg:openssl/openssl = 1.1.1
pkg:openssl/openssl = 1.1.1a
pkg:openssl/openssl = 1.1.1b
pkg:openssl/openssl = 1.1.1c
pkg:openssl/openssl = 1.1.1d
pkg:openssl/openssl = 1.1.1e
pkg:openssl/openssl = 1.1.1f
pkg:openssl/openssl = 1.1.1g
pkg:openssl/openssl = 1.1.1h
pkg:openssl/openssl = 1.1.1i
pkg:openssl/openssl = 1.1.1j
pkg:openssl/openssl = 1.1.1k
pkg:openssl/openssl = 1.1.1l
pkg:openssl/openssl = 1.1.1m
pkg:openssl/openssl = 1.1.1n
pkg:openssl/openssl = 1.1.1o
pkg:openssl/openssl = 1.0.2
pkg:openssl/openssl = 1.0.2a
pkg:openssl/openssl = 1.0.2b
pkg:openssl/openssl = 1.0.2c
pkg:openssl/openssl = 1.0.2d
pkg:openssl/openssl = 1.0.2e
pkg:openssl/openssl = 1.0.2f
pkg:openssl/openssl = 1.0.2g
pkg:openssl/openssl = 1.0.2h
pkg:openssl/openssl = 1.0.2i
pkg:openssl/openssl = 1.0.2j
pkg:openssl/openssl = 1.0.2k
pkg:openssl/openssl = 1.0.2l
pkg:openssl/openssl = 1.0.2m
pkg:openssl/openssl = 1.0.2n
pkg:openssl/openssl = 1.0.2o
pkg:openssl/openssl = 1.0.2p
pkg:openssl/openssl = 1.0.2q
pkg:openssl/openssl = 1.0.2r
pkg:openssl/openssl = 1.0.2s
pkg:openssl/openssl = 1.0.2t
pkg:openssl/openssl = 1.0.2u
pkg:openssl/openssl = 1.0.2v
pkg:openssl/openssl = 1.0.2w
pkg:openssl/openssl = 1.0.2x
pkg:openssl/openssl = 1.0.2y
pkg:openssl/openssl = 1.0.2za
pkg:openssl/openssl = 1.0.2zb
pkg:openssl/openssl = 1.0.2zc
pkg:openssl/openssl = 1.0.2zd
pkg:openssl/openssl = 1.0.2ze
Package Fixed Version
pkg:openssl/openssl = 3.0.4
pkg:openssl/openssl = 1.1.1p
pkg:openssl/openssl = 1.0.2zf
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:openssl/openssl openssl = 3.0.4
Fixed pkg:openssl/openssl openssl = 1.1.1p
Fixed pkg:openssl/openssl openssl = 1.0.2zf
Affected pkg:openssl/openssl openssl = 3.0.0
Affected pkg:openssl/openssl openssl = 3.0.1
Affected pkg:openssl/openssl openssl = 3.0.2
Affected pkg:openssl/openssl openssl = 3.0.3
Affected pkg:openssl/openssl openssl = 1.1.1
Affected pkg:openssl/openssl openssl = 1.1.1a
Affected pkg:openssl/openssl openssl = 1.1.1b
Affected pkg:openssl/openssl openssl = 1.1.1c
Affected pkg:openssl/openssl openssl = 1.1.1d
Affected pkg:openssl/openssl openssl = 1.1.1e
Affected pkg:openssl/openssl openssl = 1.1.1f
Affected pkg:openssl/openssl openssl = 1.1.1g
Affected pkg:openssl/openssl openssl = 1.1.1h
Affected pkg:openssl/openssl openssl = 1.1.1i
Affected pkg:openssl/openssl openssl = 1.1.1j
Affected pkg:openssl/openssl openssl = 1.1.1k
Affected pkg:openssl/openssl openssl = 1.1.1l
Affected pkg:openssl/openssl openssl = 1.1.1m
Affected pkg:openssl/openssl openssl = 1.1.1n
Affected pkg:openssl/openssl openssl = 1.1.1o
Affected pkg:openssl/openssl openssl = 1.0.2
Affected pkg:openssl/openssl openssl = 1.0.2a
Affected pkg:openssl/openssl openssl = 1.0.2b
Affected pkg:openssl/openssl openssl = 1.0.2c
Affected pkg:openssl/openssl openssl = 1.0.2d
Affected pkg:openssl/openssl openssl = 1.0.2e
Affected pkg:openssl/openssl openssl = 1.0.2f
Affected pkg:openssl/openssl openssl = 1.0.2g
Affected pkg:openssl/openssl openssl = 1.0.2h
Affected pkg:openssl/openssl openssl = 1.0.2i
Affected pkg:openssl/openssl openssl = 1.0.2j
Affected pkg:openssl/openssl openssl = 1.0.2k
Affected pkg:openssl/openssl openssl = 1.0.2l
Affected pkg:openssl/openssl openssl = 1.0.2m
Affected pkg:openssl/openssl openssl = 1.0.2n
Affected pkg:openssl/openssl openssl = 1.0.2o
Affected pkg:openssl/openssl openssl = 1.0.2p
Affected pkg:openssl/openssl openssl = 1.0.2q
Affected pkg:openssl/openssl openssl = 1.0.2r
Affected pkg:openssl/openssl openssl = 1.0.2s
Affected pkg:openssl/openssl openssl = 1.0.2t
Affected pkg:openssl/openssl openssl = 1.0.2u
Affected pkg:openssl/openssl openssl = 1.0.2v
Affected pkg:openssl/openssl openssl = 1.0.2w
Affected pkg:openssl/openssl openssl = 1.0.2x
Affected pkg:openssl/openssl openssl = 1.0.2y
Affected pkg:openssl/openssl openssl = 1.0.2za
Affected pkg:openssl/openssl openssl = 1.0.2zb
Affected pkg:openssl/openssl openssl = 1.0.2zc
Affected pkg:openssl/openssl openssl = 1.0.2zd
Affected pkg:openssl/openssl openssl = 1.0.2ze
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...