[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2OPENSSL-SNAPSAFE-2023-001 --- openssl-snapsafe

ID: oval:org.secpod.oval:def:1701785Date: (C)2023-10-26   (M)2024-01-29
Class: PATCHFamily: unix




A flaw was found in OpenSSL. The issue in CVE-2022-1292 did not find other places in the `c_rehash` script where it possibly passed the file names of certificates being hashed to a command executed through the shell. Some operating systems distribute this script in a manner where it is automatically executed. On these operating systems, this flaw allows an attacker to execute arbitrary commands with the privileges of the script

Platform:
Amazon Linux 2
Product:
openssl-snapsafe
Reference:
ALAS2OPENSSL-SNAPSAFE-2023-001
CVE-2022-2068
CVE    1
CVE-2022-2068
CPE    1
cpe:/o:amazon:linux:2

© SecPod Technologies