[USN-5402-1] OpenSSL vulnerabilities
Several security issues were fixed in OpenSSL.
Elison Niven discovered that OpenSSL incorrectly handled the c_rehash
script. A local attacker could possibly use this issue to execute arbitrary
commands when c_rehash is run. (CVE-2022-1292)
Raul Metsma discovered that OpenSSL incorrectly verified certain response
signing certificates. A remote attacker could possibly use this issue to
spoof certain response signing certificates. This issue only affected
Ubuntu 22.04 LTS. (CVE-2022-1343)
Tom Colley discovered that OpenSSL used the incorrect MAC key in the
RC4-MD5 ciphersuite. In non-default configurations were RC4-MD5 is enabled,
a remote attacker could possibly use this issue to modify encrypted
communications. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-1434)
Aliaksei Levin discovered that OpenSSL incorrectly handled resources when
decoding certificates and keys. A remote attacker could possibly use this
issue to cause OpenSSL to consume resources, leading to a denial of
service. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-1473)
- ID
- USN-5402-1
- Severity
- medium
- URL
- https://ubuntu.com/security/notices/USN-5402-1
- Published
-
2022-05-04T13:21:13
(2 years ago) - Modified
-
2022-05-04T13:21:13
(2 years ago) - Other Advisories
-
- ALAS-2022-1605
- ALAS2-2022-1801
- ALAS2-2022-1815
- ALAS2-2024-2502
- ALPINE:CVE-2022-1343
- ALPINE:CVE-2022-1434
- ALPINE:CVE-2022-1473
- ALSA-2022:5818
- ALSA-2022:6224
- DSA-5139-1
- ELSA-2022-5818
- ELSA-2022-6224
- ELSA-2022-9683
- ELSA-2022-9751
- FEDORA-2022-b651cb69e6
- FEDORA-2022-c9c02865f6
- FREEBSD:8E150606-08C9-11ED-856E-D4C9EF517024
- FREEBSD:FCEB2B08-CB76-11EC-A06F-D4C9EF517024
- GLSA-202210-02
- MS:CVE-2022-1292
- RHSA-2022:5818
- RHSA-2022:6224
- RLSA-2022:5818
- RUSTSEC-2022-0025
- RUSTSEC-2022-0026
- RUSTSEC-2022-0027
- SECADV-20220503-1
- SECADV-20220503-2
- SECADV-20220503-3
- SECADV-20220503-4
- SSA:2022-124-02
- SSA:2022-174-01
- SSA:2022-179-03
- SUSE-SU-2022:2068-1
- SUSE-SU-2022:2075-1
- SUSE-SU-2022:2098-1
- SUSE-SU-2022:2106-1
- SUSE-SU-2022:2182-1
- SUSE-SU-2022:2197-1
- SUSE-SU-2022:2251-1
- SUSE-SU-2022:2251-2
- SUSE-SU-2022:2306-1
- SUSE-SU-2022:2308-1
- SUSE-SU-2022:2321-1
- USN-5402-2
- USN-6457-1
- USN-7018-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:deb/ubuntu/openssl?distro=jammy | ubuntu | openssl | < 3.0.2-0ubuntu1.1 | jammy | ||
Affected | pkg:deb/ubuntu/openssl?distro=impish | ubuntu | openssl | < 1.1.1l-1ubuntu1.3 | impish | ||
Affected | pkg:deb/ubuntu/openssl?distro=focal | ubuntu | openssl | < 1.1.1f-1ubuntu2.13 | focal | ||
Affected | pkg:deb/ubuntu/openssl?distro=bionic | ubuntu | openssl | < 1.1.1-1ubuntu2.1~18.04.17 | bionic | ||
Affected | pkg:deb/ubuntu/openssl1.0?distro=bionic | ubuntu | openssl1.0 | < 1.0.2n-1ubuntu5.9 | bionic | ||
Affected | pkg:deb/ubuntu/libssl3?distro=jammy | ubuntu | libssl3 | < 3.0.2-0ubuntu1.1 | jammy | ||
Affected | pkg:deb/ubuntu/libssl1.1?distro=impish | ubuntu | libssl1.1 | < 1.1.1l-1ubuntu1.3 | impish | ||
Affected | pkg:deb/ubuntu/libssl1.1?distro=focal | ubuntu | libssl1.1 | < 1.1.1f-1ubuntu2.13 | focal | ||
Affected | pkg:deb/ubuntu/libssl1.1?distro=bionic | ubuntu | libssl1.1 | < 1.1.1-1ubuntu2.1~18.04.17 | bionic | ||
Affected | pkg:deb/ubuntu/libssl1.0.0?distro=bionic | ubuntu | libssl1.0.0 | < 1.0.2n-1ubuntu5.9 | bionic | ||
Affected | pkg:deb/ubuntu/libssl1.0-dev?distro=bionic | ubuntu | libssl1.0-dev | < 1.0.2n-1ubuntu5.9 | bionic | ||
Affected | pkg:deb/ubuntu/libssl-doc?distro=jammy | ubuntu | libssl-doc | < 3.0.2-0ubuntu1.1 | jammy | ||
Affected | pkg:deb/ubuntu/libssl-doc?distro=impish | ubuntu | libssl-doc | < 1.1.1l-1ubuntu1.3 | impish | ||
Affected | pkg:deb/ubuntu/libssl-doc?distro=focal | ubuntu | libssl-doc | < 1.1.1f-1ubuntu2.13 | focal | ||
Affected | pkg:deb/ubuntu/libssl-doc?distro=bionic | ubuntu | libssl-doc | < 1.1.1-1ubuntu2.1~18.04.17 | bionic | ||
Affected | pkg:deb/ubuntu/libssl-dev?distro=jammy | ubuntu | libssl-dev | < 3.0.2-0ubuntu1.1 | jammy | ||
Affected | pkg:deb/ubuntu/libssl-dev?distro=impish | ubuntu | libssl-dev | < 1.1.1l-1ubuntu1.3 | impish | ||
Affected | pkg:deb/ubuntu/libssl-dev?distro=focal | ubuntu | libssl-dev | < 1.1.1f-1ubuntu2.13 | focal | ||
Affected | pkg:deb/ubuntu/libssl-dev?distro=bionic | ubuntu | libssl-dev | < 1.1.1-1ubuntu2.1~18.04.17 | bionic |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |