Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-1292
Description:The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2022.1943   1.3.6.1.4.1.25623.1.1.2.2022.2877   1.3.6.1.4.1.25623.1.1.2.2022.2215   1.3.6.1.4.1.25623.1.1.2.2022.2329   1.3.6.1.4.1.25623.1.1.2.2022.2118   1.3.6.1.4.1.25623.1.1.2.2022.2548   1.3.6.1.4.1.25623.1.1.2.2022.2360   1.3.6.1.4.1.25623.1.1.2.2022.2629   1.3.6.1.4.1.25623.1.1.10.2022.0173   1.3.6.1.4.1.25623.1.1.2.2022.2098   1.3.6.1.4.1.25623.1.1.13.2022.174.01   1.3.6.1.4.1.25623.1.1.2.2022.2895   1.3.6.1.4.1.25623.1.1.2.2022.1909   1.3.6.1.4.1.25623.1.1.2.2022.1924   1.3.6.1.4.1.25623.1.1.2.2022.2396   1.3.6.1.4.1.25623.1.1.2.2023.2162   1.3.6.1.4.1.25623.1.0.820857   1.3.6.1.4.1.25623.1.1.4.2022.2106.1   1.3.6.1.4.1.25623.1.1.2.2022.1977   1.3.6.1.4.1.25623.1.1.2.2022.2578   1.3.6.1.4.1.25623.1.1.2.2022.2007   1.3.6.1.4.1.25623.1.0.893008   1.3.6.1.4.1.25623.1.0.148306   1.3.6.1.4.1.25623.1.1.4.2022.2068.1   1.3.6.1.4.1.25623.1.1.2.2022.2419   1.3.6.1.4.1.25623.1.1.13.2022.124.02   1.3.6.1.4.1.25623.1.1.2.2022.2168   1.3.6.1.4.1.25623.1.1.13.2022.179.03   1.3.6.1.4.1.25623.1.0.705139   1.3.6.1.4.1.25623.1.1.4.2022.2075.1   1.3.6.1.4.1.25623.1.1.2.2023.1281   1.3.6.1.4.1.25623.1.1.2.2023.2431   1.3.6.1.4.1.25623.1.0.148307   1.3.6.1.4.1.25623.1.0.820799   1.3.6.1.4.1.25623.1.1.4.2022.2098.1   1.3.6.1.4.1.25623.1.0.148045   1.3.6.1.4.1.25623.1.1.2.2022.2300   1.3.6.1.4.1.25623.1.1.2.2022.2143   1.3.6.1.4.1.25623.1.1.2.2022.2432   1.3.6.1.4.1.25623.1.1.2.2022.2228   1.3.6.1.4.1.25623.1.0.148046   1.3.6.1.4.1.25623.1.1.2.2022.2446  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-1292
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1ad73b4d27bd8c1b369a3cd453681d3a4f1bb9b2
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=548d3f280a6e737673f5b61fce24bb100108dfeb
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=e5fd1728ef4c7a5bf7c7a7163ca60370460a6e23
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0011
https://security.netapp.com/advisory/ntap-20220602-0009/
https://www.openssl.org/news/secadv/20220503.txt
Debian Security Information: DSA-5139 (Google Search)
https://www.debian.org/security/2022/dsa-5139
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VX4KWHPMKYJL6ZLW4M5IU7E5UV5ZWJQU/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZNU5M7BXMML26G3GPYKFGQYPQDRSNKDD/
https://security.gentoo.org/glsa/202210-02
https://cert-portal.siemens.com/productcert/pdf/ssa-953464.pdf
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpujul2022.html
https://lists.debian.org/debian-lts-announce/2022/05/msg00019.html




© 1998-2025 E-Soft Inc. All rights reserved.