Active Topics

 


Reply
Thread Tools
Posts: 333 | Thanked: 32 times | Joined on Jul 2007
#1

Luciano Bello discovered that the random number generator in Debian's openssl package is predictable. This is caused by an incorrect Debian-specific change to the openssl package (CVE-2008-0166). As a result, cryptographic key material may be guessable.

This is a Debian-specific vulnerability which does not affect other operating systems which are not based on Debian. However, other systems can be indirectly affected if weak keys are imported into them.

It is strongly recommended that all cryptographic key material which has been generated by OpenSSL versions starting with 0.9.8c-1 on Debian systems is recreated from scratch. Furthermore, all DSA keys ever used on affected Debian systems for signing or authentication purposes should be considered compromised; the Digital Signature Algorithm relies on a secret random value used during signature generation.

The first vulnerable version, 0.9.8c-1, was uploaded to the unstable distribution on 2006-09-17, and has since that date propagated to the testing and current stable (etch) distributions. The old stable distribution (sarge) is not affected.

Affected keys include SSH keys, OpenVPN keys, DNSSEC keys, and key material for use in X.509 certificates and session keys used in SSL/TLS connections. Keys generated with GnuPG or GNUTLS are not affected, though.

A detector fo
Debian Security Advisory
http://www.debian.org/security/2008/dsa-1571

Exploit
http://metasploit.com/users/hdm/tools/debian-openssl/
 
Bundyo's Avatar
Posts: 4,708 | Thanked: 4,649 times | Joined on Oct 2007 @ Bulgaria
#2
You're approximately the third.
__________________
Technically, there are three determinate states the cat could be in: Alive, Dead, and Bloody Furious.
 
Posts: 333 | Thanked: 32 times | Joined on Jul 2007
#3
Havn't had time to fully read all the lastest posts but did but see it before I posted...,

Are you talking about the Bug or the Exploit and per Generated Keys

Originally Posted by Bundyo View Post
You're approximately the third.
 
Posts: 333 | Thanked: 32 times | Joined on Jul 2007
#4
 
luca's Avatar
Posts: 1,137 | Thanked: 402 times | Joined on Sep 2007 @ Catalunya
#5
I think this time the fact that maemo has old software it's a good thing:
Code:
 $ ssh -v
OpenSSH_4.7p1  Debian-2.maemo2, OpenSSL 0.9.7e 25 Oct 2004
 
Reply


 
Forum Jump


All times are GMT. The time now is 21:00.