http://www.debian.org/security/2008/dsa-1571
http://www.ubuntu.com/usn/usn-612-1
http://metasploit.com/users/hdm/tools/debian-openssl/
Note that only upgrading the packages wont fix the problem, the affected keys need to be regenerated.
http://wiki.debian.org/SSLkeys
-
wearetheborg Notebook Virtuoso
-
I think I heard that all the linux systems are vulnerable and not just debian and debian based.Is that true?
-
I, yesterday I think, received an automated ssl update from ubuntu....fix?
-
(copyright xkcd) -
wearetheborg Notebook Virtuoso
Note that only upgrading the packages wont fix the problem, the affected keys need to be regenerated.
http://wiki.debian.org/SSLkeys
Only if you are using keys generated on a debian system.Last edited by a moderator: May 8, 2015 -
It was caused by a patch made by a Debian developer, and it stayed only inside the Debian distribution (and distros based on Debian like Ubuntu). It didn't go upstream into the main SSH tree, so there's little to no danger of other distros also being compromised unless they took from Debian's patches without noting it.
ALERT: Debian / Ubuntu SSL vulnerability
Discussion in 'Linux Compatibility and Software' started by wearetheborg, May 16, 2008.