CLSA-2022-1657814965
Dashboard / Vulnerabilities / CLSA-2022-1657814965
CLSA-2022-1657814965
Summary: Fix CVE(s): CVE-2022-1473, CVE-2022-1292, CVE-2022-2068
Details: * SECURITY REGRESSION: Invalid fix for CVE-2022-1473 - debian/patches/CVE-2022-1473.patch: removing unnecessary patch since this version is actually not affected * SECURITY UPDATE: c_rehash script allows command injection - debian/patches/CVE-2022-1292.patch: switch to upstream patch, and apply it before c_rehash-compat.patch - debian/patches/CVE-2022-2068.patch: fix file operations in tools/c_rehash.in - debian/patches/c_rehash-compat.patch: updated patch to apply after the security updates - CVE-2022-2068
Affected packages
Package
Name: libssl-dev
Purl: pkg:deb/tuxcare/libssl-dev?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
