VDB
BDU%3A2022-06608
BDU%3A2022-06608
PUBLISHED
CVSS 10 CRITICAL
Уязвимость функционала проверки сертификата X.509 библиотеки OpenSSL, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Сообщество свободного программного обеспечения, Novell Inc., Fedora Project, Canonical Ltd., Red Hat Inc., OpenSSL Software Foundation | Debian GNU/Linux, OpenSUSE Leap, Fedora, Suse Linux Enterprise Server, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Server for SAP Applications, Ubuntu, Red Hat Enterprise Linux, SUSE Manager Retail Branch Server, SUSE Manager Proxy, SUSE Manager Server, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Module for Basesystem, OpenSSL |
Timeline
- Nov 2, 2022 CVE Published
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
References
- https://security-tracker.debian.org/tracker/CVE-2022-3602 url
- https://www.suse.com/security/cve/CVE-2022-3602.html url
- https://access.redhat.com/security/cve/CVE-2022-3602 url
- http://www.openwall.com/lists/oss-security/2022/11/01/15 url
- http://www.openwall.com/lists/oss-security/2022/11/01/16 url
- http://www.openwall.com/lists/oss-security/2022/11/01/17 url
- http://www.openwall.com/lists/oss-security/2022/11/01/18 url
- http://www.openwall.com/lists/oss-security/2022/11/01/19 url
- http://www.openwall.com/lists/oss-security/2022/11/01/20 url
- http://www.openwall.com/lists/oss-security/2022/11/01/21 url
- http://www.openwall.com/lists/oss-security/2022/11/01/24 url
- https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fe3b639dc19b325846f4f6801f2f4604f56e3de3 url
- https://www.openssl.org/news/secadv/20221101.txt advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/63YRPWPUSX3MBHNPIEJZDKQT6YA7UF6S/ advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DWP23EZYOBDJQP7HP4YU7W2ABU2YDITS/ advisory
- https://ubuntu.com/security/notices/USN-5710-1 advisory