[CLSA-2022:1657816312] Fixed CVEs in openssl: CVE-2022-2068, CVE-2022-1292
Type:
security
Severity:
Critical
Release date:
2022-07-14
Description:
- CVE-2022-1292: c_rehash: Do not use shell to invoke openssl to prevent command injection - CVE-2022-2068: c_rehash: Fix file operations to prevent command injection
Updated packages:
  • openssl-perl-1.0.1e-63.el6.tuxcare.els7.x86_64.rpm
    sha:dd836313d1ee36d8a9ad5d9778504489be6fba5f
  • openssl-devel-1.0.1e-63.el6.tuxcare.els7.x86_64.rpm
    sha:a4b962dd575e8877de1984eb4d3185732e9cb511
  • openssl-static-1.0.1e-63.el6.tuxcare.els7.x86_64.rpm
    sha:14358d3d3229d11e31d4625ef7eca7743a0e0c03
  • openssl-1.0.1e-63.el6.tuxcare.els7.x86_64.rpm
    sha:3369f47688b224ec785f2dc1e57d674d2ad3eb2c
  • openssl-devel-1.0.1e-63.el6.tuxcare.els7.i686.rpm
    sha:e72be4e4f75b6e1641014b9a65d6a415470aacde
  • openssl-1.0.1e-63.el6.tuxcare.els7.i686.rpm
    sha:d2bc19d12345dd83a72b77b19365359bdfa109d9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.