Description
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3008-1 | openssl security update |
Debian DSA |
DSA-5139-1 | openssl security update |
Ubuntu USN |
USN-5402-1 | OpenSSL vulnerabilities |
Ubuntu USN |
USN-5402-2 | OpenSSL vulnerabilities |
Ubuntu USN |
USN-6457-1 | Node.js vulnerabilities |
Ubuntu USN |
USN-7018-1 | OpenSSL vulnerabilities |
Ubuntu USN |
USN-7060-1 | EDK II vulnerabilities |
References
History
Wed, 13 Aug 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 11 Aug 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens brownfield Connectivity Gateway |
|
| CPEs | cpe:2.3:a:siemens:brownfield_connectivity_gateway:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Siemens
Siemens brownfield Connectivity Gateway |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 05 May 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Netapp
Subscribe
A250
Subscribe
A250 Firmware
Subscribe
A700s
Subscribe
A700s Firmware
Subscribe
Active Iq Unified Manager
Subscribe
Aff 500f
Subscribe
Aff 500f Firmware
Subscribe
Aff 8300
Subscribe
Aff 8300 Firmware
Subscribe
Aff 8700
Subscribe
Aff 8700 Firmware
Subscribe
Aff A400
Subscribe
Aff A400 Firmware
Subscribe
Clustered Data Ontap
Subscribe
Clustered Data Ontap Antivirus Connector
Subscribe
Fabric-attached Storage A400
Subscribe
Fabric-attached Storage A400 Firmware
Subscribe
Fas 500f
Subscribe
Fas 500f Firmware
Subscribe
Fas 8300
Subscribe
Fas 8300 Firmware
Subscribe
Fas 8700
Subscribe
Fas 8700 Firmware
Subscribe
H300e
Subscribe
H300e Firmware
Subscribe
H300s
Subscribe
H300s Firmware
Subscribe
H410s
Subscribe
H410s Firmware
Subscribe
H500e
Subscribe
H500e Firmware
Subscribe
H500s
Subscribe
H500s Firmware
Subscribe
H700e
Subscribe
H700e Firmware
Subscribe
H700s
Subscribe
H700s Firmware
Subscribe
Oncommand Insight
Subscribe
Oncommand Workflow Automation
Subscribe
Santricity Smi-s Provider
Subscribe
Smi-s Provider
Subscribe
Snapcenter
Subscribe
Snapmanager
Subscribe
Solidfire\, Enterprise Sds \& Hci Storage Node
Subscribe
Solidfire \& Hci Management Node
Subscribe
Openssl
Subscribe
Openssl
Subscribe
Oracle
Subscribe
Enterprise Manager Ops Center
Subscribe
Mysql Server
Subscribe
Mysql Workbench
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Jboss Core Services
Subscribe
Jboss Enterprise Web Server
Subscribe
Rhel Satellite Client
Subscribe
Satellite
Subscribe
Satellite Capsule
Subscribe
Siemens
Subscribe
Brownfield Connectivity Gateway
Subscribe
Status: PUBLISHED
Assigner: openssl
Published:
Updated: 2025-12-30T04:55:25.734Z
Reserved: 2022-04-11T00:00:00.000Z
Link: CVE-2022-1292
Updated: 2025-08-13T14:06:18.130Z
Status : Modified
Published: 2022-05-03T16:15:18.823
Modified: 2025-08-13T14:15:28.717
Link: CVE-2022-1292
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN