CVE-2022-1292 log

Source
Severity Medium
Remote Unknown
Type Unknown
Description
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection.  This script is distributed by some operating systems in a manner where it is automatically executed.  On such operating systems, an attacker could execute arbitrary commands with the rivileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool.
Group Package Affected Fixed Severity Status Ticket
AVG-2731 lib32-openssl-1.0 1.0.2.zd-1 1.0.2.ze-1 Medium Unknown
AVG-2730 openssl-1.0 1.0.2.zd-1 1.0.2.ze-1 Medium Unknown
AVG-2702 openssl 1.1.1.n-1 1.1.1.o-1 Medium Fixed
References
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=1ad73b4d27bd8c1b369a3cd453681d3a4f1bb9b2
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=e5fd1728ef4c7a5bf7c7a7163ca60370460a6e23