In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze).
Project Subscriptions
| Vendors | Products |
|---|---|
|
Broadcom
Subscribe
|
Sannav
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Netapp
Subscribe
|
Aff 8300
Subscribe
Aff 8300 Firmware
Subscribe
Aff 8700
Subscribe
Aff 8700 Firmware
Subscribe
Aff A400
Subscribe
Aff A400 Firmware
Subscribe
Bootstrap Os
Subscribe
Element Software
Subscribe
Fas 8300
Subscribe
Fas 8300 Firmware
Subscribe
Fas 8700
Subscribe
Fas 8700 Firmware
Subscribe
Fas A400
Subscribe
Fas A400 Firmware
Subscribe
H300s
Subscribe
H300s Firmware
Subscribe
H410c
Subscribe
H410c Firmware
Subscribe
H410s
Subscribe
H410s Firmware
Subscribe
H500s
Subscribe
H500s Firmware
Subscribe
H610c
Subscribe
H610c Firmware
Subscribe
H610s
Subscribe
H610s Firmware
Subscribe
H615c
Subscribe
H615c Firmware
Subscribe
H700s
Subscribe
H700s Firmware
Subscribe
Hci Compute Node
Subscribe
Hci Management Node
Subscribe
Ontap Antivirus Connector
Subscribe
Ontap Select Deploy Administration Utility
Subscribe
Santricity Smi-s Provider
Subscribe
Smi-s Provider
Subscribe
Snapmanager
Subscribe
Solidfire
Subscribe
|
|
Openssl
Subscribe
|
Openssl
Subscribe
|
|
Redhat
Subscribe
|
|
|
Siemens
Subscribe
|
Sinec Ins
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5169-1 | openssl security update |
Ubuntu USN |
USN-5488-1 | OpenSSL vulnerability |
Ubuntu USN |
USN-5488-2 | OpenSSL vulnerability |
Ubuntu USN |
USN-6457-1 | Node.js vulnerabilities |
Ubuntu USN |
USN-7018-1 | OpenSSL vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 15 Sep 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 05 May 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: openssl
Published:
Updated: 2025-12-30T04:55:27.130Z
Reserved: 2022-06-13T00:00:00.000Z
Link: CVE-2022-2068
Updated: 2025-11-03T21:45:47.155Z
Status : Modified
Published: 2022-06-21T15:15:09.060
Modified: 2025-11-03T22:15:58.023
Link: CVE-2022-2068
OpenCVE Enrichment
No data.
Debian DSA
Ubuntu USN