OS Command Injection in OpenSSL - CVE-2022-2068

 

OS Command Injection in OpenSSL - CVE-2022-2068

Published: June 21, 2022 / Updated: October 5, 2022


Vulnerability identifier: #VU64559
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-2068
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
OpenSSL
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux for Scientific Computing
Fedora
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Desktop
IBM AIX
SUSE Linux Enterprise Storage
IBM i
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Server
Oracle Solaris
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Legacy Software
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Slackware Linux
Ubuntu
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
openEuler
Security Directory Integrator
Telemetry Dashboard
RecoverPoint Classic
Liquidware
IBM Virtualization Engine TS7700 3948-VED
Citrix Workspace App
Webex App VDI
Db2 Rest
ObjectScale
IBM Aspera Shares
Secured Component Verification (SCV)
PowerStore T
EMC ECS
IBM Cloud Pak for Watson AIOps
Platform Automation Toolkit
DB2 Warehouse on Cloud Pak for Data
DB2 on Cloud Pak for Data
Watson Studio on Cloud Pak for Data
Solutions Enabler
Unisphere 360
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
eVASA Provider Virtual Appliance
VASA Provider Standalone
IBM Security Verify Directory
Dell Data Protection Central
GT SoftGOT2000
SINEC INS
Dell EMC Storage Monitoring and Reporting (SMR)
Submariner
Gatekeeper Operator
IBM MQ Operator
IBM Spectrum Copy Data Management
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
EasyApache
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
OpenShift Logging
IBM Spectrum Control
IBM Sterling Connect:Direct for UNIX
Red Hat Satellite
IBM Rational Build Forge
Tenable Nessus
Oracle SD-WAN Edge
IBM Spectrum Protect Plus
Dell EMC Data Protection Search
NetWorker
Netcool Operations Insight
IBM SANnav Management Portal
Red Hat OpenShift distributed tracing (RHOSDT)
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Cloud Transformation Advisor
IBM Aspera Orchestrator
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Dell Secure Connect Gateway
PowerProtect Data Domain
IBM Rational ClearCase
IBM Rational ClearQuest
Red Hat OpenStack
PowerProtect Data Manager
IBM Robotic Process Automation
Self Node Remediation Operator
OpenShift sandboxed containers
Multicluster Engine for Kubernetes
OpenShift Service Mesh
Node Maintenance Operator
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Solutions Enabler Virtual Appliance
OpenShift API for Data Protection (OADP)
openssl (Debian package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libssl1.0.0 (Ubuntu package)
openssl (Ubuntu package)
yggdrasil-worker-forwarder (Red Hat package)
foreman_ygg_worker (Red Hat package)
yggdrasil (Red Hat package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
libopenssl0_9_8-debuginfo-32bit
libopenssl0_9_8-32bit
libopenssl0_9_8-debuginfo
libopenssl0_9_8
compat-openssl098-debugsource
qpid-proton (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
libopenssl1_0_0-hmac-32bit
openssl-doc
libopenssl-devel
libopenssl1_0_0
libopenssl1_0_0-32bit
libopenssl1_0_0-debuginfo
libopenssl1_0_0-debuginfo-32bit
libopenssl1_0_0-hmac
openssl
openssl-debuginfo
openssl-debugsource
openssl-1_0_0-debuginfo
openssl-1_0_0-doc
libopenssl-1_0_0-devel
libopenssl-1_0_0-devel-32bit
openssl-1_0_0-debugsource
openssl-1_0_0
openssl1.0 (Ubuntu package)
openssl-1_0_0-cavs-debuginfo
openssl-1_0_0-cavs
libopenssl1_0_0-steam-debuginfo
libopenssl1_0_0-steam
libopenssl10
libopenssl10-debuginfo
libopenssl1_0_0-steam-32bit-debuginfo
libopenssl1_0_0-steam-32bit
libopenssl1_0_0-32bit-debuginfo
libopenssl1_1-hmac-32bit
libopenssl-1_1-devel
libopenssl1_1
libopenssl1_1-debuginfo
libopenssl1_1-hmac
openssl-1_1
openssl-1_1-debuginfo
openssl-1_1-debugsource
libopenssl1_1-32bit
libopenssl1_1-32bit-debuginfo
libopenssl-1_1-devel-32bit
libopenssl1_1-debuginfo-32bit
openssl-1_1-doc
openssl-libs
openssl-devel
openssl-help
openssl11
openssl-perl
openssl (Red Hat package)
openssl1.1
rubygem-foreman_maintain (Red Hat package)
jws5-tomcat-native (Red Hat package)
pulpcore-selinux (Red Hat package)
tfm-rubygem-safemode (Red Hat package)
rubygem-safemode (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
tfm-rubygem-rchardet (Red Hat package)
rubygem-rchardet (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
tfm-rubygem-git (Red Hat package)
rubygem-git (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
intel-sgx-ssl
intel-sgx-ssl-devel
libsgx-ra-uefi
libsgx-dcap-ql-devel
libsgx-dcap-quote-verify-devel
libsgx-ae-pce
sgx-pck-id-retrieval-tool
libsgx-epid
libsgx-aesm-pce-plugin
libsgx-ae-qe3
libsgx-dcap-default-qpl
libsgx-aesm-ecdsa-plugin
libsgx-pce-logic
libsgx-launch-devel
libsgx-ra-network
sgx-aesm-service
libsgx-dcap-ql
linux-sgx
libsgx-ra-uefi-devel
libsgx-aesm-launch-plugin
libsgx-dcap-default-qpl-devel
libsgx-enclave-common-devel
libsgx-ae-le
libsgx-qe3-logic
libsgx-ae-qve
sgxsdk
libsgx-quote-ex
libsgx-uae-service
linux-sgx-debugsource
sgx-dcap-pccs
sgx-ra-service
libsgx-epid-devel
libsgx-aesm-quote-ex-plugin
libsgx-enclave-common
libsgx-launch
libsgx-ra-network-devel
libsgx-dcap-quote-verify
libsgx-quote-ex-devel
libsgx-ae-epid
libsgx-urts
libsgx-aesm-epid-plugin
linux-sgx-debuginfo
openssl3
libopenssl-3-devel
openssl-3-debuginfo
libopenssl3-32bit-debuginfo
libopenssl3
libopenssl3-debuginfo
libopenssl3-32bit
libopenssl-3-devel-32bit
openssl-3-doc
openssl-3-debugsource
openssl-3
foreman (Red Hat package)
python-gitpython (Red Hat package)
python-django (Red Hat package)
foreman-installer (Red Hat package)
python-pulpcore (Red Hat package)
rubygem-katello (Red Hat package)
satellite (Red Hat package)
rubygem-foreman_rh_cloud (Red Hat package)
puppet-agent (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
rubygem-foreman_theme_satellite (Red Hat package)
libnode-dev (Ubuntu package)
libnode72 (Ubuntu package)
nodejs (Ubuntu package)
nodejs-doc (Ubuntu package)
Migration Toolkit for Containers
Nessus Network Monitor
Red Hat OpenShift Container Platform
Traffix SDC
IBM App Connect Professional
VMware Horizon Client
JBoss Core Services
IBM VIOS
EMC Integrated Data Protection Appliance
Splunk Enterprise
Dell EMC NetWorker vProxy
IBM Aspera Faspex for Windows
IBM Aspera Faspex for Linux
IBM Integrated Analytics System
JBoss Web Server
Red Hat Ceph Storage
Splunk Universal Forwarder
Zimbra Collaboration
Virtualization Engine TS7700 3957-VEC
Virtualization Engine TS7700 3957-VED
RUGGEDCOM ROX MX5000RE
RUGGEDCOM ROX RX1400
RUGGEDCOM ROX MX5000
RUGGEDCOM ROX RX1501
RUGGEDCOM ROX RX1500
RUGGEDCOM ROX RX5000
RUGGEDCOM ROX RX1536
RUGGEDCOM ROX RX1524
RUGGEDCOM ROX RX1512
RUGGEDCOM ROX RX1511
RUGGEDCOM ROX RX1510
FOS Firmware
PowerScale OneFS
IBM Security Verify Access
Cisco Jabber
Cisco Webex Meetings
Communications Unified Assurance
Cloud Pak for Security (CP4S)
Integrated Data protection Appliance (IDPA)
Data Protection Search
NetWorker Management Console
Dell EMC VxRail Appliance
Gaia
IBM InfoSphere Information Server

Detailed vulnerability description

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation in the c_rehash script distributed by some operating systems. A remote attacker with ability to pass data to c_rehash script can and execute arbitrary OS commands with the privileges of the script.

The vulnerability exists due to incomplete fix for #VU62765 (CVE-2022-1292).


How to mitigate CVE-2022-2068

Install updates from vendor's website.

Sources