Luciano Bello discovered that the random number generator in Debian's openssl package is predictable. As a result, cryptographic key material may be guessable.
Systems other than Debian can be indirectly affected if weak keys are imported into them.
openssl packageDebian generates weak ssl keysDigg Linux/Unix upcoming Thu, 06/26/2008 - 04:27
Luciano Bello discovered that the random number generator in Debian's openssl package is predictable. As a result, cryptographic key material may be guessable. Ubuntu/Debian, and security bug in OpensslDigg Linux/Unix upcoming Mon, 06/16/2008 - 08:24
A very dangerous security bug discovered in openssl debian/ubuntu packages. The random number generator in Debian's openssl package is predictable. Debian Flaw Alllows SSL Keys to be CrackedDigg Linux/Unix upcoming Fri, 05/23/2008 - 13:14
According to an announcement on the debian.org security lists, a flaw in the random number generator of debian's openssl package has the potential to make any cryptographic key material generated by it guessable. Debian's worst nightmare - and how it came aboutDebian-News.net Thu, 05/22/2008 - 14:10
The Debian GNU/Linux project has just endured what is probably its worst week on the security front in the 15 years of its existence following the disclosure on May 13 of a serious vulnerability in the distribution's OpenSSL package. Get your SSL and SSH keys updatedUbuntu-News.net Sat, 05/17/2008 - 13:47
On May 13th, 2008 the Debian project announced that Luciano Bello found an interesting vulnerability in the OpenSSL package they were distributing. Impact of the Debian OpenSSL vulnerabilityLWN.net Fri, 05/16/2008 - 06:13
CentOS looks at the impact of the Debian SSL vulnerability for CentOS users. "This vulnerability can affect CentOS machines through the use of keys that were generated with the OpenSSL package from Debian. Debian: Flaw in OpenSSL makes private keys predictableDigg Linux/Unix upcoming Tue, 05/13/2008 - 15:16
Luciano Bello discovered that the random number generator in Debian'sopenssl package is predictable. This is caused by an incorrectDebian-specific change to the openssl package (CVE-2008-0166). Cryptographic weakness on Debian systemsLWN.net Tue, 05/13/2008 - 03:55
The Debian project has sent out an advisory stating that, due to a Debian-specific modification to the openssl package, cryptographic keys generated on affected systems may be guessable. Tags:
|