Ink brush drawing by David Mack

About Matt

Matt Neely a penetration tester and security researcher located in the Cleveland Ohio area.

Learn more here.

Search
Powered by Squarespace
« New Penetration Testing Webcast by Ed Skoudis | Main | Twitter »
Tuesday
May132008

Critical Ubuntu and Debian Vulnerability

Ubuntu and Debian users take note. Today Ubuntu and Debian released patches to the OpenSSL package to fix a critical vulnerability in how the package generates encryption keys. Roughly two years ago the maintainers removed the call to the system's random number generator. This makes all keys generated on affected systems predictable. This vulnerability affects SSH keys, OpenVPN keys, DNSSEC keys, SSL/TLS session keys and key material in X.509 certificates.

Any Ubuntu or Debian users should download and install the updated packs and regenerate any keys made in the past two years.

Here is a link to the advisory:
http://www.debian.org/security/2008/dsa-1571
http://www.ubuntu.com/usn/usn-612-1

Cheers,
Matt

P.S. Special thanks to Chris for bringing this to my attention.

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>