[USN-5402-2] OpenSSL vulnerabilities
Severity
Medium
Affected Packages
4
CVEs
2
Several security issues were fixed in OpenSSL.
USN-5402-1 fixed several vulnerabilities in OpenSSL. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Elison Niven discovered that OpenSSL incorrectly handled the c_rehash
script. A local attacker could possibly use this issue to execute arbitrary
commands when c_rehash is run. (CVE-2022-1292)
Aliaksei Levin discovered that OpenSSL incorrectly handled resources when
decoding certificates and keys. A remote attacker could possibly use this
issue to cause OpenSSL to consume resources, leading to a denial of
service. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-1473)
Package | Affected Version |
---|---|
pkg:deb/ubuntu/openssl?distro=xenial | < 1.0.2g-1ubuntu4.20+esm3 |
pkg:deb/ubuntu/libssl1.0.0?distro=xenial | < 1.0.2g-1ubuntu4.20+esm3 |
pkg:deb/ubuntu/libssl-doc?distro=xenial | < 1.0.2g-1ubuntu4.20+esm3 |
pkg:deb/ubuntu/libssl-dev?distro=xenial | < 1.0.2g-1ubuntu4.20+esm3 |
- ID
- USN-5402-2
- Severity
- medium
- URL
- https://ubuntu.com/security/notices/USN-5402-2
- Published
-
2022-05-26T13:34:08
(2 years ago) - Modified
-
2022-05-26T13:34:08
(2 years ago) - Other Advisories
-
- ALAS-2022-1605
- ALAS2-2022-1801
- ALAS2-2022-1815
- ALAS2-2024-2502
- ALPINE:CVE-2022-1473
- ALSA-2022:5818
- ALSA-2022:6224
- DSA-5139-1
- ELSA-2022-5818
- ELSA-2022-6224
- ELSA-2022-9683
- ELSA-2022-9751
- FEDORA-2022-b651cb69e6
- FEDORA-2022-c9c02865f6
- FREEBSD:8E150606-08C9-11ED-856E-D4C9EF517024
- FREEBSD:FCEB2B08-CB76-11EC-A06F-D4C9EF517024
- GLSA-202210-02
- MS:CVE-2022-1292
- RHSA-2022:5818
- RHSA-2022:6224
- RLSA-2022:5818
- RUSTSEC-2022-0025
- SECADV-20220503-1
- SECADV-20220503-4
- SSA:2022-124-02
- SSA:2022-174-01
- SSA:2022-179-03
- SUSE-SU-2022:2068-1
- SUSE-SU-2022:2075-1
- SUSE-SU-2022:2098-1
- SUSE-SU-2022:2106-1
- SUSE-SU-2022:2182-1
- SUSE-SU-2022:2197-1
- SUSE-SU-2022:2251-1
- SUSE-SU-2022:2251-2
- SUSE-SU-2022:2306-1
- SUSE-SU-2022:2308-1
- SUSE-SU-2022:2321-1
- USN-5402-1
- USN-6457-1
- USN-7018-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:deb/ubuntu/openssl?distro=xenial | ubuntu | openssl | < 1.0.2g-1ubuntu4.20+esm3 | xenial | ||
Affected | pkg:deb/ubuntu/libssl1.0.0?distro=xenial | ubuntu | libssl1.0.0 | < 1.0.2g-1ubuntu4.20+esm3 | xenial | ||
Affected | pkg:deb/ubuntu/libssl-doc?distro=xenial | ubuntu | libssl-doc | < 1.0.2g-1ubuntu4.20+esm3 | xenial | ||
Affected | pkg:deb/ubuntu/libssl-dev?distro=xenial | ubuntu | libssl-dev | < 1.0.2g-1ubuntu4.20+esm3 | xenial |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |