Go Back   The UNIX and Linux Forums > Special Forums > Security > Security Advisories (RSS)
.
google site



Security Advisories (RSS) UNIX and Linux Security Advisories Via RSS News

Closed Thread
English Japanese Spanish French German Portuguese Italian Powered by Powered by Google
 
Thread Tools Search this Thread Rate Thread Display Modes
  #1 (permalink)  
Old 06-18-2008
Linux Bot's Avatar
Forum Robot Girl
 

Join Date: Sep 2000
Posts: 23,299
USN-612-11: openssl-blacklist update

Description:
=========================================================== Ubuntu Security Notice USN-612-11 June 18, 2008 openssl-blacklist update http://www.ubuntu.com/usn/usn-612-1 http://www.ubuntu.com/usn/usn-612-3 http://www.ubuntu.com/usn/usn-612-8 http://www.ubuntu.com/usn/usn-612-9 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 7.04 Ubuntu 7.10 Ubuntu 8.04 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: openssl-blacklist 0.3.3+0.4-0ubuntu0.6.06.2 openssl-blacklist-extra 0.3.3+0.4-0ubuntu0.6.06.2 Ubuntu 7.04: openssl-blacklist 0.3.3+0.4-0ubuntu0.7.04.2 openssl-blacklist-extra 0.3.3+0.4-0ubuntu0.7.04.2 Ubuntu 7.10: openssl-blacklist 0.3.3+0.4-0ubuntu0.7.10.2 openssl-blacklist-extra 0.3.3+0.4-0ubuntu0.7.10.2 Ubuntu 8.04 LTS: openssl-blacklist 0.3.3+0.4-0ubuntu0.8.04.3 openssl-blacklist-extra 0.3.3+0.4-0ubuntu0.8.04.3 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: USN-612-3 addressed a weakness in OpenSSL certificate and key generation and introduced openssl-blacklist to aid in detecting vulnerable certificates and keys. This update adds RSA-4096 blacklists to the openssl-blacklist-extra package and adjusts openssl-vulnkey to properly handle RSA-4096 and higher moduli. Original advisory details: A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH, OpenVPN and SSL certificates.





More...
Sponsored Links
Closed Thread

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
USN-612-9: openssl-blacklist update Linux Bot Security Advisories (RSS) 0 06-12-2008 10:00 PM
Ubuntu: openssl-blacklist update Linux Bot Security Advisories (RSS) 0 05-21-2008 02:50 PM
USN-612-8: openssl-blacklist update Linux Bot Security Advisories (RSS) 0 05-21-2008 01:40 PM
rm substitute with blacklist broli UNIX for Dummies Questions & Answers 2 12-06-2007 08:13 AM
openssl help hassan2 UNIX for Advanced & Expert Users 2 10-31-2002 01:59 PM



All times are GMT -4. The time now is 10:52 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2010. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0