CVE-2022-2068
published 2022-06-21CVE-2022-2068: In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise…
PriorityP261high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
96.28%
99.9th percentile
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze).
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssl | < openssl 3.0.4-1 (bookworm) | openssl 3.0.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_openssl_1.1.1k-17_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_openssl_1.1.1k-12_on_cbl_mariner_1.0 | — | — |
| nodejs | nodejs | >= 0 < 12.22.9~dfsg-1ubuntu3.1 | 12.22.9~dfsg-1ubuntu3.1 |
| openssl | openssl | >= 0 < 1.1.1n-0+deb11u3 | 1.1.1n-0+deb11u3 |
| openssl | openssl | >= 0 < 3.0.4-1 | 3.0.4-1 |
| openssl | openssl | >= 0 < 3.0.4-1 | 3.0.4-1 |
| openssl | openssl | >= 0 < 3.0.4-1 | 3.0.4-1 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.27+esm10 | 1.0.1f-1ubuntu2.27+esm10 |
| openssl | openssl | >= 1.0.2 < 1.0.2zf | 1.0.2zf |
| openssl | openssl | >= 1.1.1 < 1.1.1p | 1.1.1p |
| openssl | openssl | >= 3.0.0 < 3.0.4 | 3.0.4 |
| paloalto | cortex_xdr | — | — |
| paloalto | pan-os | — | — |
| siemens | sinec_ins | < 1.0 | 1.0 |
| siemens | sinec_ins | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered when file names of certificates being hashed are passed unsanitized to a shell command within the c_rehash script — monitor for unexpected shell metacharacter usage or child process spawning from c_rehash execution ↗
- →On systems where c_rehash is automatically executed, an attacker can trigger arbitrary OS command execution by placing a specially crafted certificate file name containing shell metacharacters in the certificate directory ↗
- →Monitor for unexpected process execution spawned by the c_rehash script (e.g., bash/sh child processes with unusual arguments), especially on systems where c_rehash runs automatically ↗
- →For ICS/OT environments, Mitsubishi Electric GT SoftGOT2000 versions 1.275M through 1.280S are affected; monitor for exploitation via specially crafted certificates sent to these devices ↗
- →On Red Hat systems, check for presence of the c_rehash script in the openssl-perl package (Optional repository); the script is not installed by default but its presence indicates exposure ↗
- ·The c_rehash script does not properly sanitise shell metacharacters in certificate file names; the incomplete fix for CVE-2022-1292 left additional injection points unaddressed ↗
- ·Red Hat systems using update-ca-trust with a single bundled certificate store are not automatically vulnerable since c_rehash is not included in default RHEL installations and is never executed automatically ↗
- ·Red Hat Satellite embeds an affected c_rehash script in puppet-agent but is not considered vulnerable because it does not execute the script with untrusted data and the scriptlet is root-owned ↗
- ·Affected OpenSSL versions span three branches: 3.0.0–3.0.3 (fixed in 3.0.4), 1.1.1–1.1.1o (fixed in 1.1.1p), and 1.0.2–1.0.2ze (fixed in 1.0.2zf) ↗
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv7.5HIGH
vendor_msrc9.8CRITICAL
vendor_oracle9.8HIGH
vendor_ubuntu7.5HIGH
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
vendor_paloalto·2024-11-07·CVSS 6.8
CVE-2014-0195 [MEDIUM] PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
PAN-SA-2024-0014 Informational Bulletin: Impact of OSS CVEs in Cortex XDR Agent
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to Cortex XDR Agent. While Cortex XDR Agent may include the
CVEs: CVE-2014-0195, CVE-2014-0224, CVE-2014-3509, CVE-2014-3512, CVE-2014-3513, CVE-2014-3567, CVE-2015-0209, CVE-2015-0292, CVE-2015-1789, CVE-2015-1791, CVE-2015-1793, CVE-2015-3194, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798, CVE-2016-0799, CVE-2016-2105, CVE-2016-2106, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176, CVE-2016-2177, CVE-2016-2179, CVE-2016-2180, CVE-2016-2181, CVE-2016-2182, CVE-2016-2183, CVE-2016-6302, CVE-2016-6303, CVE-2016-6304, CVE-2019-1551, CVE-2019-1552, CVE-2019-1559, CVE-2019-1563, CVE-2020-196
Oracle
Oracle Oracle Communications Risk Matrix: Platform (OpenSSL) — CVE-2022-2068
vendor_oracle·2024-10-15·CVSS 9.8
CVE-2022-2068 [HIGH] Oracle Oracle Communications Risk Matrix: Platform (OpenSSL) — CVE-2022-2068
Oracle Oracle Communications Risk Matrix: Platform (OpenSSL) vulnerability
CVE: CVE-2022-2068
CVSS: 9.8
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2024-09-18·CVSS 3.7
CVE-2024-0727 [LOW] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Robert Merget, Marcus Brinkmann, Nimrod Aviram, and Juraj Somorovsky
discovered that certain Diffie-Hellman ciphersuites in the TLS
specification and implemented by OpenSSL contained a flaw. A remote
attacker could possibly use this issue to eavesdrop on encrypted
communications. This was fixed in this update by removing the insecure
ciphersuites from OpenSSL. (CVE-2020-1968)
Paul Kehrer discovered that OpenSSL incorrectly handled certain input
lengths in EVP functions. A remote attacker could possibly use this issue
to cause OpenSSL to crash, resulting in a denial of service.
(CVE-2021-23840)
Elison Niven discovered that OpenSSL incorrectly handled the c_rehash
script. A local attacker could possibl
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Ubuntu
Node.js vulnerabilities
vendor_ubuntu·2023-10-30·CVSS 7.5
CVE-2022-0778 [HIGH] Node.js vulnerabilities
Title: Node.js vulnerabilities
Summary: Several security issues were fixed in Node.js.
Tavis Ormandy discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2022-0778)
Elison Niven discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to execute
arbitrary code. (CVE-2022-1292)
Chancen and Daniel Fiala discovered that Node.js incorrectly handled certain
inputs. If a user or an automated system were tricked into opening a specially
crafted input file, a remote attacker c
CISA ICS
Siemens RUGGEDCOM ROX
cisa_ics·2023-07-13
Siemens RUGGEDCOM ROX
ICS Advisory
##
Siemens RUGGEDCOM ROX
Release DateJuly 13, 2023
Alert CodeICSA-23-194-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM ROX
- Vulnerabilities: Cleartext Transmission of Sensitive Information, Command Injection, Improper Authentication, Classic Buffer Overflow, Uncontrolled Resource Consumption, Improper Certificate Validation, Cross-Site Request Forgery (CSRF), Improper Input Validation, Incorrect Default Permissions, Cross-site Scripting, Inadequate Encryption Strength, Use of a Broken or Risky Cryptographic Algorithm.
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to send a malformed HTTP packet c
CISA ICS
Siemens SIMATIC S7-1500 TM MFP Linux Kernel
cisa_ics·2023-06-15·CVSS 5.5
[MEDIUM] Siemens SIMATIC S7-1500 TM MFP Linux Kernel
ICS Advisory
##
Siemens SIMATIC S7-1500 TM MFP Linux Kernel
Release DateJune 15, 2023
Alert CodeICSA-23-166-11
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely / low attack complexity / public exploits available
- Vendor: Siemens ProductCERT
- Equipment: SIMATIC S7-1500 TM MFP
- Vulnerabilities: Multiple vulnerabilities
## 2. RISK EVALUATION
Exploitation of these vulnerabilities could lead to denial-of-service, crashing t
CISA ICS
Siemens SINEC INS
cisa_ics·2023-01-17·CVSS 7.3
[HIGH] Siemens SINEC INS
ICS Advisory
##
Siemens SINEC INS
Last RevisedJanuary 17, 2023
Alert CodeICSA-23-017-03
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.9
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerabilities: OS Command Injection, Inadequate Encryption Strength, Out-of-bounds Write, HTTP Request Smuggling, Inadequate Encryption Strength, Use of Insufficiently Random Values, Authentication Bypass by Spoofing, Path Trave
CISA ICS
Mitsubishi Electric GT SoftGOT2000
cisa_ics·2022-11-15·CVSS 7.3
[HIGH] Mitsubishi Electric GT SoftGOT2000
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Mitsubishi Electric GT SoftGOT2000
Last RevisedNovember 15, 2022
Alert CodeICSA-22-319-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Mitsubishi Electric Corporation
- Equipment: GT SoftGOT2000
- Vulnerability: Operating System (OS) Command Injection
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to execute malicious OS commands.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Mitsubishi Electric reports this vulnerability affects OpenSSL in the following products:
Oracle
Oracle Oracle Communications Applications Risk Matrix: User Interface (OpenSSL) — CVE-2022-2068
vendor_oracle·2022-10-15·CVSS 9.8
CVE-2022-2068 [HIGH] Oracle Oracle Communications Applications Risk Matrix: User Interface (OpenSSL) — CVE-2022-2068
Oracle Oracle Communications Applications Risk Matrix: User Interface (OpenSSL) vulnerability
CVE: CVE-2022-2068
CVSS: 9.8
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Ubuntu
OpenSSL vulnerability
vendor_ubuntu·2022-07-06
CVE-2022-2068 OpenSSL vulnerability
Title: OpenSSL vulnerability
Summary: OpenSSL could be made to crash or run programs when the c_rehash script is
used.
USN-5488-1 fixed vulnerabilities in OpenSSL. This update provides the
corresponding updates for Ubuntu 16.04 ESM.
Original advisory details:
Chancen and Daniel Fiala discovered that OpenSSL incorrectly handled the
c_rehash script. A local attacker could possibly use this issue to execute
arbitrary commands when c_rehash is run.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openssl: the c_rehash script allows command injection
vendor_redhat·2022-06-21·CVSS 7.3
CVE-2022-2068 [HIGH] CWE-77 openssl: the c_rehash script allows command injection
openssl: the c_rehash script allows command injection
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash
Ubuntu
OpenSSL vulnerability
vendor_ubuntu·2022-06-21
CVE-2022-2068 OpenSSL vulnerability
Title: OpenSSL vulnerability
Summary: OpenSSL could be made to crash or run programs when the c_rehash script is
used.
Chancen and Daniel Fiala discovered that OpenSSL incorrectly handled the
c_rehash script. A local attacker could possibly use this issue to execute
arbitrary commands when c_rehash is run.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
The c_rehash script allows command injection
vendor_msrc·2022-06-14·CVSS 9.8
CVE-2022-2068 [HIGH] CWE-78 The c_rehash script allows command injection
The c_rehash script allows command injection
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
openssl: openssl
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.micros
Debian
CVE-2022-2068: openssl - In addition to the c_rehash shell command injection identified in CVE-2022-1292,...
vendor_debian·2022·CVSS 7.3
CVE-2022-2068 [HIGH] CVE-2022-2068: openssl - In addition to the c_rehash shell command injection identified in CVE-2022-1292,...
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0
OSV
openssl vulnerabilities
osv·2024-09-18·CVSS 3.7
CVE-2020-1968 [LOW] openssl vulnerabilities
openssl vulnerabilities
Robert Merget, Marcus Brinkmann, Nimrod Aviram, and Juraj Somorovsky
discovered that certain Diffie-Hellman ciphersuites in the TLS
specification and implemented by OpenSSL contained a flaw. A remote
attacker could possibly use this issue to eavesdrop on encrypted
communications. This was fixed in this update by removing the insecure
ciphersuites from OpenSSL. (CVE-2020-1968)
Paul Kehrer discovered that OpenSSL incorrectly handled certain input
lengths in EVP functions. A remote attacker could possibly use this issue
to cause OpenSSL to crash, resulting in a denial of service.
(CVE-2021-23840)
Elison Niven discovered that OpenSSL incorrectly handled the c_rehash
script. A local attacker could possibly use this issue to execute arbitrary
commands when c_rehash is
OSV
nodejs vulnerabilities
osv·2023-10-30·CVSS 7.5
CVE-2022-0778 [HIGH] nodejs vulnerabilities
nodejs vulnerabilities
Tavis Ormandy discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2022-0778)
Elison Niven discovered that Node.js incorrectly handled certain inputs. If a
user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to execute
arbitrary code. (CVE-2022-1292)
Chancen and Daniel Fiala discovered that Node.js incorrectly handled certain
inputs. If a user or an automated system were tricked into opening a specially
crafted input file, a remote attacker could possibly use this issue to execute
arbitrary code. (CVE-2022
OSV
heap buffer overflow in OpenSSL version 3.0.4
osv·2022-06-28·CVSS 7.3
CVE-2022-2068 [HIGH] heap buffer overflow in OpenSSL version 3.0.4
heap buffer overflow in OpenSSL version 3.0.4
In OpenSSL version 3.0.4 a heap buffer overflow exists in the AVX512 support that can be attacked via network resulting in code execution. This is reachable via four code paths: RSAZ 1024, RSAZ 512, Dual 1024 RSAZ, and Default constant-time Montgomery modular exponentiation. Please note this issue is especially serious as OpenSSL 3.0.4 contains a security fix for CVE-2022-2068 which allows arbitrary code execution. This means that all users of OpenSSL 3 are affected by a number of serious security vulnerabilities. Intel AXV-512 support is present in Intel CPUs releases including Knights Landing (Xeon Phi x200, 2016), Knights Mill (Xeon Phi x205, 2017), Skylake-SP, Skylake-X (2017), Cannon Lake (2018), Cascade Lake (2019), Cooper Lake (2020), I
GHSA
GHSA-xjxr-x4h8-946x: In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly san
ghsa_unreviewed·2022-06-22·CVSS 7.3
CVE-2022-2068 [HIGH] CWE-78 GHSA-xjxr-x4h8-946x: In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly san
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0
OSV
CVE-2022-2068: In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly san
osv·2022-06-21·CVSS 7.3
CVE-2022-2068 [HIGH] CVE-2022-2068: In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly san
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0
No detection rules found.
No public exploits indexed.
Qualys
Oracle Critical Patch Update, October 2024 Security Update Review
blogs_qualys·2024-10-16
Oracle Critical Patch Update, October 2024 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Oracle released the last quarterly edition of this year’s Critical Patch Update. The update contains patches for 334 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 100 constituting about 30% of the total patches released. Oracle MySQL and Oracle Fusion Middleware followed, with 45 and 32 security patches, respectively.
244
Qualys
Oracle Critical Patch Security Update: October 2024 | Qualys
blogs_qualys·2024-10-16
Oracle Critical Patch Security Update: October 2024 | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Oracle released the last quarterly edition of this year’s Critical Patch Update. The update contains patches for 334 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 100 constituting about 30% of the total patches released. Oracle MySQL and Oracle Fusion Middleware followed, with 45 and 32 security patches, respectively.
Checkpoint
23rd January – Threat Intelligence Report
blogs_checkpoint·2023-01-23·CVSS 9.8
CVE-2022-42475 [CRITICAL] 23rd January – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 23rd January – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 23rd January, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
The fast food brand ‘Yum! Brands’, operator of leading fast food restaurants including KFC, Pizza Hut and Taco Bell, has been targeted by a ransomware attack. The attack lead to the temporary closure of almost 300 breaches in the United Kingdom. No group has taken claim at this point.
Vice Society ransomware gang has claim
arXiv
One for All and All for One: GNN-based Control-Flow Attestation for Embedded Devices
arxiv_fulltext·2024-03-12
One for All and All for One: GNN-based Control-Flow Attestation for Embedded Devices
One for All and All for One:\ -based Control-Flow Attestation for Embedded Devices
Marco Chilese1, Richard Mitev1, Meni Orenbach2,
Robert Thorburn3, Ahmad Atamli23, Ahmad-Reza Sadeghi1 5px
1Technical University of Darmstadt, 2NVIDIA, 3 University of Southampton
## Abstract
Control-Flow Attestation (CFA) is a security service that allows an entity (verifier) to verify the integrity of code execution on a remote computer system (prover). Existing CFA schemes suffer from impractical assumptions, such as requiring access to the prover's internal state (e.g., memory or code), the complete Control-Flow Graph (CFG) of the prover's software, large sets of measurements, or tailor-made hardware. Moreover, current CFA schemes are inadequate for attesting embedded systems due to their high computat
arXiv
Free Proxies Unmasked: A Vulnerability and Longitudinal Analysis of Free Proxy Services
arxiv_fulltext·2024-03-04
Free Proxies Unmasked: A Vulnerability and Longitudinal Analysis of Free Proxy Services
cyanrgb0.4,1,1
orangergb1,0.7,0
dkgreenrgb0,0.6,0
grayrgb0.5,0.5,0.5
purplergb0.58,0,0.82
[3]#1#2: #3
[1]redTODO: #1
redREFS
[1]brownAntoine#1
[1]orangePierre#1
[1]magentaNaif#1
[1]purpleWalter#1
[1]dkgreen#1
[1]orange#1
[1]red#1
[1]#1
[1]#1
[1]#1
[1]3pt plus 1pt minus 1pt #1.75em minus .5em
et al.
i.e.,\
e.g.,\
black!60whiteRedacted
Datadome
Free Proxies Unmasked: A Vulnerability and Longitudinal Analysis of Free Proxy Services
Anonymous Authors*
Naif Mehanna
Univ. Lille, Inria, CNRS
[email protected]
Walter Rudametkin
Univ. Rennes, Inria,
CNRS, IRISA, IUF
[email protected]
Pierre Laperdrix
CNRS, Univ. Lille, Inria
[email protected]
Antoine Vastel
Datadome
[email protected]
\@IEEEpubidpullup6.5
7.57.5 Workshop on Measurements, Attac
Bugzilla
CVE-2022-2068 openssl: the c_rehash script allows command injection
bugzilla·2022-06-15·CVSS 7.3
CVE-2022-2068 [HIGH] CVE-2022-2068 openssl: the c_rehash script allows command injection
CVE-2022-2068 openssl: the c_rehash script allows command injection
When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script.
Discussion:
Created edk2 tracking bugs for this issue:
Affects: fedora-all [bug 2099974]
Created mingw-openssl tracking bugs for this issue:
Affects: fedora-all [bug 2099971]
Created openssl tracking bugs for this issue:
Affects: fedora-all [bug 2099972]
Created openssl1.1 tracking bugs for this issue:
https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdfhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2c9c35870601b4a44d86ddbf512b38df38285cfahttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=7a9c027159fe9e1bbc2cd38a8a2914bff0d5abd9https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9639817dac8bbbaa64d09efad7464ccc405527c7https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WZZBKUHQFGSKGNXXKICSRPL7AMVW5M5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/https://security.netapp.com/advisory/ntap-20220707-0008/https://www.debian.org/security/2022/dsa-5169https://www.openssl.org/news/secadv/20220621.txthttp://seclists.org/fulldisclosure/2024/Nov/0https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdfhttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=2c9c35870601b4a44d86ddbf512b38df38285cfahttps://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=7a9c027159fe9e1bbc2cd38a8a2914bff0d5abd9https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=9639817dac8bbbaa64d09efad7464ccc405527c7https://gitlab.com/fraf0/cve-2022-1292-re_score-analysishttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6WZZBKUHQFGSKGNXXKICSRPL7AMVW5M5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA/https://security.netapp.com/advisory/ntap-20220707-0008/https://www.debian.org/security/2022/dsa-5169https://www.openssl.org/news/secadv/20220621.txt
2022-06-21
Published