|
from: trivia
debian and the openssl flaw June 2nd, 2008 Ben Laurie wrote about the Debian SSL problem a couple of weeks ago ... (CVE-2008-0166). As a result, cryptographic key material may be guessable…….. affected keys include SSH keys
from: CAcert NEWS Blog
Recently discovered predictable RSA and DSA key generation vulnerabilities occurring in Debian OpenSSL packages[1][2]. As many Linux distributions are based of Debian derived distributions like the popular Ubuntu, Knoppix, Kubuntu distributions, there are a significant number of vulnerable RSA and DSA private keys around now
from: System Advancements at the Monastery
Scanner for Debian OpenSSL Vulnerability May 22nd, 2008 by abbot [ Vulnerability] ... host keys as identified in CVE-2008-0166. The fingerprints are taken from keys generated by HD Moore’
from: CAcert NEWS Blog
Recently discovered predictable RSA and DSA key generation vulnerabilities occuring in Debian OpenSSL packages[1][2]. As many Linux distributions are based of Debian derived distributions like the popular Ubuntu, Knoppix, Kubuntu distributions, there are a significant number of vulnerable RSA and DSA private keys around now
from: Linux More
DSA 1576-2: New openssh packages fix predictable randomness Posted by Daniela Mehler The Debian Security Team published a new ... type : remote Debian-specific: yes CVE Id(s) : CVE-2008-0166 Matt Zimmerman discovered
from: Scott Golightly's Blog
Debian OpenSSL Vulnerability I got this from an issue of the RISKS digest ... : In Mitre's CVE dictionary: CVE-2008-0166. More information: Luciano Bello discovered ... by an incorrect Debian-specific change to the openssl package (CVE-2008-0166). As a result, cryptographic key
from: .::anti-abuse.com::.: Security Revealed
Debian Security Advisory 1576-1 - The recently announced vulnerability in Debian’s openssl package (DSA-1571-1, CVE-2008-0166) indirectly affects OpenSSH. As a result, all user and host keys
from: Security
Sun is not affected by the OpenSSL random number generator weakness vulnerability described in CVE-2008-0166 and CERT Vulnerability Note VU#925211. The versions of OpenSSL bundled with Solaris 10
from: Netmonic Company Blog
A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system
from: Gert@X
OpenSSL Vulnerability in Debian May 13th, 2008 or Debian based distros! Like Ubuntu. I actually dont feel like blogging this, but . ... by an incorrect Debian-specific change to the openssl package (CVE-2008-0166). As a result, cryptographic
from: Don’t fear the penguin
Copying from SANS Internet Storm Center diary: Debian and Ubuntu Linux users should look into their OpenSSH setup. It turns out the used PRNG ( ... be enough to get the key itself compromised. CVE-2008-0166 Ubuntu: USN-612-1 Debian: DSA-1571-1
from: Pythian Group Blog
Debian OpenSSL Package Introduces Vulnerability May 13th, 2008 - by Don Seiler The highlight today of probably every Linux-related mailing list and IRC channel was the announcement of CVE-2008-0166, affecting OpenSSL libraries on Debian-based Linux
from: Marshall Mar -- The Blog
The media is currently overflown with this news. Debians openssl package included a patch that introduced a vulnerability to Debian systems and its ... change to the openssl package (CVE-2008-0166). As a result, cryptographic key material may
from: rolfs.no: Experiencing weblogging
A predictability of the random number is not good. It makes the randomness predictable, which makes it just predictable ... . It is a Debian-specific remote vulnerability. It got CVE Id: CVE-2008-0166. Here is a perl script
from: linux.gen.nz
http://www.debian.org/security/2008/dsa-1571 “Luciano Bello discovered that the random number generator in Debian’s openssl package is predictable. This is caused by an incorrect Debian-specific change to the openssl package (CVE-2008-0166). As a result, cryptographic key material may be guessable.” And “It is strongly recommended
from: Views on Life
or Debian based distros! Like Ubuntu. I actually dont feel like blogging this, but .. I feel I should mention it ... change to the openssl package (CVE-2008-0166). As a result, cryptographic key material may
from: On the way to inifinity
Debian SSL/SSH key flaw! Apparently the SSL crypto has a dubious and easily crackable method. This link is to a security advisory for Linux! ... =========================================================== Ubuntu Security Notice USN-612-1 May 13, 2008 openssl vulnerability CVE-2008-0166
from: Blog B
Now for a little trek into geek territory: A couple of days ago a vulnerability was found in the random number generators used to create secure SSH, ... ://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0166 DSA: http://lists.debian.org/debian-security
from: Sexiest tinfoil hat, ever!
For those of my friends running Debian, Ubuntu or a Debian derivative… or have keys that were generated on a Debian (or related) ... CVE-2008-0166 =========================================================== A weakness ... . (CVE-2008-0166) This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu
from: MindTouch, Inc Blog
Since the 8.05 Jay Cooke VM release, Debian has announced several security updates which affect the Deki Wiki VM ... : The recently announced vulnerability in Debian’s openssl package (DSA-1571-1, CVE-2008-0166
from: MDLog:/sysadmin
Yesterday, 13 May 2008, was a really bad day for the Debian project, probably one of the worst days in the history of Debian. Luciano Bello discovered that the random number generator in Debian’s openssl package is predictable. This is caused by an incorrect Debian-specific change to the openssl package (CVE-2008-0166
from: Daily cyber threats and internet security news
Debian.org Accounts Blocked Due To Recent OpenSSL Vulnerabilities Recently discovered weakness in debian OpenSSL’s random number generator, ... to the OpenSSL package (CVE-2008-0166). As a result, cryptographic key material may be guessable
from: Penguin in a Wheatfield
Major Linux Vulnerability: Debian PRNG May 15, 2008 by haytkir Two days ago this vulnerability was released: http://www.debian ... package (CVE-2008-0166). As a result, cryptographic key material may be guessable
|