File _patchinfo of Package patchinfo.24565

<patchinfo incident="24565">
  <issue tracker="bnc" id="1185637">openssl-1_1 fails to build after 2022-06-01</issue>
  <issue tracker="bnc" id="1199166">VUL-0: CVE-2022-1292: openssl,openssl-1_0_0,openssl1,openssl-3,compat-openssl098,openssl-1_1: command injection in c_rehash</issue>
  <issue tracker="bnc" id="1201099">VUL-0: EMBARGOED: CVE-2022-2097: openssl-1_1,openssl-3: AES OCB fails to encrypt some bytes</issue>
  <issue tracker="bnc" id="1200550">VUL-0: CVE-2022-2068: openssl,openssl1,openssl-1_1,openssl-1_0_0: more shell code injection issues in c_rehash</issue>
  <issue tracker="cve" id="2022-2068"/>
  <issue tracker="cve" id="2022-2097"/>
  <issue tracker="cve" id="2022-1292"/>
  <packager>jsikes</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for openssl-1_1</summary>
  <description>This update for openssl-1_1 fixes the following issues:

- CVE-2022-1292: Fixed command injection in c_rehash (bsc#1199166).
- CVE-2022-2068: Fixed more shell code injection issues in c_rehash. (bsc#1200550)
- CVE-2022-2097: Fixed partial missing encryption in AES OCB mode (bsc#1201099).
</description>
</patchinfo>
openSUSE Build Service is sponsored by