Welcome, Guest. Please login or register.

Author Topic: Serious security vulnerability on Debian/Ubuntu  (Read 1210 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline PiruTopic starter

  • \' union select name,pwd--
  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 6946
    • Show only replies by Piru
    • http://www.iki.fi/sintonen/
Serious security vulnerability on Debian/Ubuntu
« on: May 13, 2008, 06:30:38 PM »
Quote
Luciano Bello discovered that the random number generator in Debian's openssl package is predictable. This is caused by an incorrect Debian-specific change to the openssl package (CVE-2008-0166). As a result, cryptographic key material may be guessable.

...

Affected keys include SSH keys, OpenVPN keys, DNSSEC keys, and key material for use in X.509 certificates and session keys used in SSL/TLS connections.

DSA-1571-1 openssl -- predictable random number generator
USN-612-2: OpenSSH vulnerability
 

Offline PiruTopic starter

  • \' union select name,pwd--
  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 6946
    • Show only replies by Piru
    • http://www.iki.fi/sintonen/
 

Offline zyphoid

  • Sr. Member
  • ****
  • Join Date: Aug 2006
  • Posts: 406
    • Show only replies by zyphoid
Re: Serious security vulnerability on Debian/Ubuntu
« Reply #2 on: May 14, 2008, 10:59:56 PM »
oh man! that needs a quick fix!
A1200T Mid-Night 060@50mhz tv tuner,voodoo banshee,usb subway,mediator,Dual Multi partition 200Gig 2.5/3.5HD, Twin dual-layer lite-on dvd 52x dvd-rw, sx-32pro030@50mhz my favorite system what xbox came from til someone says otherwise,A500 Efika...
 

Offline PiruTopic starter

  • \' union select name,pwd--
  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 6946
    • Show only replies by Piru
    • http://www.iki.fi/sintonen/
Re: Serious security vulnerability on Debian/Ubuntu
« Reply #3 on: May 15, 2008, 12:44:49 AM »
There fix is there already. The problem is that not everyone updates their boxes daily.
 

Offline lorddef

  • Hero Member
  • *****
  • Join Date: Apr 2002
  • Posts: 1139
    • Show only replies by lorddef
    • http://
Re: Serious security vulnerability on Debian/Ubuntu
« Reply #4 on: May 15, 2008, 06:01:57 PM »
Patched our servers yesterday morning.
Restraining orders are just another way of saying I love you!
 

Offline leirbag28

Re: Serious security vulnerability on Debian/Ubuntu
« Reply #5 on: May 15, 2008, 07:01:27 PM »
@zyphoid

 How about selling me your favorite system? :-)
CD32 is actually the best Amiga ever made by Commodore!...