Security update for openssl-3
This update for openssl-3 fixes the following issues: - CVE-2022-2068: Fixed more shell code injection issues in c_rehash. (bsc#1200550) - CVE-2022-1292: Properly sanitise shell metacharacters in c_rehash script. (bsc#1199166) - CVE-2022-1343: Fixed incorrect signature verification in OCSP_basic_verify (bsc#1199167). - CVE-2022-2097: Fixed partial missing encryption in AES OCB mode (bsc#1201099). - CVE-2022-1434: Fixed incorrect MAC key used in the RC4-MD5 ciphersuite (bsc#1199168). - CVE-2022-1473: Fixed resource leakage when decoding certificates and keys (bsc#1199169).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for openssl-3 fixes the following issues: - CVE-2022-2068: Fixed more shell code injection issues in c_rehash. (bsc#1200550) - CVE-2022-1292: Properly sanitise shell metacharacters in c_rehash script. (bsc#1199166) - CVE-2022-1343: Fixed incorrect signature verification in OCSP_basic_verify (bsc#1199167). - CVE-2022-2097: Fixed partial missing encryption in AES OCB mode (bsc#1201099). - CVE-2022-1434: Fixed incorrect MAC key used in the RC4-MD5 ciphersuite (bsc#1199168). - CVE-2022-1473: Fixed resource leakage when decoding certificates and keys (bsc#1199169).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1185637
- https://bugzilla.suse.com/1199166
- https://bugzilla.suse.com/1199167
- https://bugzilla.suse.com/1199168
- https://bugzilla.suse.com/1199169
- https://bugzilla.suse.com/1200550
- https://bugzilla.suse.com/1201099
- https://www.suse.com/security/cve/CVE-2022-1292
- https://www.suse.com/security/cve/CVE-2022-1343
- https://www.suse.com/security/cve/CVE-2022-1434
- https://www.suse.com/security/cve/CVE-2022-1473
- https://www.suse.com/security/cve/CVE-2022-2068
- https://www.suse.com/security/cve/CVE-2022-2097
- https://www.suse.com/support/update/announcement/2022/suse-su-20222306-1/