Stories
Slash Boxes
Comments
typodupeerror delete not in

Comments: 1 +-   Debian bug let hackers guess private SSL/SSH keys-> on Tuesday May 13 2008, @09:11AM SecurityBob

Submitted by SecurityBob on Tuesday May 13 2008, @09:11AM
debian
SecurityBob writes "Debian package maintainers tend to very often modify the source code of the package they are maintaining so that it better fits into the distribution itself. However, most of the time, there changes are not sent back to upstream for validation, which might cause some tension between upstream developers and Debian packagers. Today, a critical security advisory has been released : a Debian packager modified the source code of OpenSSL back in 2006 so as to remove the seeding of OpenSSL random number generator, which in turns makes cryptographical key material generated on a Debian system guessable. The solution ? Upgrade OpenSSL and re-generate all your SSH and SSL keys. This problem not only affects Debian, but also all its derivatives, such as Ubuntu."
Link to Original Source
submission

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
Don't vote -- it only encourages them!