[CLSA-2022:1657817606] Fixed CVEs in openssl: CVE-2022-1292, CVE-2022-2068
Type:
security
Severity:
Critical
Release date:
2022-07-14
Description:
- CVE-2022-1292: c_rehash: Do not use shell to invoke openssl to prevent command injection - CVE-2022-2068: c_rehash: Fix file operations to prevent command injection
Updated packages:
  • openssl-devel-1.0.1e-63.el6.tuxcare.els7.i686.rpm
    sha:cae8bb0b9318f43dc3faf18c589db3e4e01abb42
  • openssl-static-1.0.1e-63.el6.tuxcare.els7.x86_64.rpm
    sha:81b788827549734eff626ec2203c0d960ffe9930
  • openssl-perl-1.0.1e-63.el6.tuxcare.els7.x86_64.rpm
    sha:682ec7969e7bd0662f1034f34e55c3c88b4acea9
  • openssl-devel-1.0.1e-63.el6.tuxcare.els7.x86_64.rpm
    sha:b27fed76646d753b936bed80cdac79928a137fe3
  • openssl-1.0.1e-63.el6.tuxcare.els7.i686.rpm
    sha:cde68338970d226a0f52ffb52c9b975c1c57505f
  • openssl-1.0.1e-63.el6.tuxcare.els7.x86_64.rpm
    sha:4aae941e7c421c9794bea74f6554e75f83dc8f78
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.