USN-5488-1: OpenSSL vulnerability
Chancen and Daniel Fiala discovered that OpenSSL incorrectly handled the crehash script. A local attacker could possibly use this issue to execute arbitrary commands when crehash is run.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this OpenSSL vulnerability?
The vulnerability ID for this OpenSSL vulnerability is CVE-2022-2068.
How does the OpenSSL vulnerability impact the system?
The OpenSSL vulnerability allows a local attacker to execute arbitrary commands when the c_rehash script is run.
Which versions of OpenSSL are affected by this vulnerability?
The versions affected by this vulnerability are 1.0.2n-1ubuntu5.10, 1.1.1-1ubuntu2.1~18.04.19, 1.1.1f-1ubuntu2.15, 1.1.1l-1ubuntu1.5, and 3.0.2-0ubuntu1.5.
How can I fix the OpenSSL vulnerability?
To fix the OpenSSL vulnerability, update the OpenSSL package to version 3.0.2-0ubuntu1.5, 1.1.1l-1ubuntu1.5, 1.1.1f-1ubuntu2.15, 1.1.1-1ubuntu2.1~18.04.19, or 1.0.2n-1ubuntu5.10 depending on your Ubuntu version.
Where can I find more information about the OpenSSL vulnerability?
You can find more information about the OpenSSL vulnerability in the following references: [USN-5488-2](https://ubuntu.com/security/notices/USN-5488-2) and [USN-6457-1](https://ubuntu.com/security/notices/USN-6457-1).