{"id":2635,"date":"2008-05-26T16:38:33","date_gmt":"2008-05-26T16:38:33","guid":{"rendered":"http:\/\/cryptogon.com\/?p=2635"},"modified":"2008-05-26T16:44:29","modified_gmt":"2008-05-26T16:44:29","slug":"debian-openssl-security-flaw","status":"publish","type":"post","link":"https:\/\/www.cryptogon.com\/?p=2635","title":{"rendered":"Debian OpenSSL Security Flaw"},"content":{"rendered":"<p>Hint to 99.98% of you reading this: Skip to the next story.<\/p>\n<p>Reader GP submitted <a href=\"http:\/\/www.technologyreview.com\/Infotech\/20801\/page1\/\">Alarming Open-Source Security Holes<\/a>, by Simson Garfinkel, which is a human readable version of <a href=\"http:\/\/www.debian.org\/security\/2008\/dsa-1571\">this Debian Security Advisory<\/a>:<\/p>\n<p><em>Luciano Bello discovered that the random number generator in Debian&#8217;s openssl package is predictable. This is caused by an incorrect Debian-specific change to the openssl package (CVE-2008-0166). As a result, cryptographic key material may be guessable.<\/p>\n<p>This is a Debian-specific vulnerability which does not affect other operating systems which are not based on Debian. However, other systems can be indirectly affected if weak keys are imported into them.<\/p>\n<p>It is strongly recommended that all cryptographic key material which has been generated by OpenSSL versions starting with 0.9.8c-1 on Debian systems is recreated from scratch. Furthermore, all DSA keys ever used on affected Debian systems for signing or authentication purposes should be considered compromised; the Digital Signature Algorithm relies on a secret random value used during signature generation.<\/p>\n<p>The first vulnerable version, 0.9.8c-1, was uploaded to the unstable distribution on 2006-09-17, and has since that date propagated to the testing and current stable (etch) distributions. The old stable distribution (sarge) is not affected.<\/p>\n<p>Affected keys include SSH keys, OpenVPN keys, DNSSEC keys, and key material for use in X.509 certificates and session keys used in SSL\/TLS connections. Keys generated with GnuPG or GNUTLS are not affected, though.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hint to 99.98% of you reading this: Skip to the next story. Reader GP submitted Alarming Open-Source Security Holes, by Simson Garfinkel, which is a human readable version of this Debian Security Advisory: Luciano Bello discovered that the random number generator in Debian&#8217;s openssl package is predictable. This is caused by an incorrect Debian-specific change [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23,12],"tags":[],"class_list":["post-2635","post","type-post","status-publish","format-standard","hentry","category-coincidence","category-technology"],"_links":{"self":[{"href":"https:\/\/www.cryptogon.com\/index.php?rest_route=\/wp\/v2\/posts\/2635","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cryptogon.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cryptogon.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cryptogon.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cryptogon.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2635"}],"version-history":[{"count":0,"href":"https:\/\/www.cryptogon.com\/index.php?rest_route=\/wp\/v2\/posts\/2635\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.cryptogon.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2635"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cryptogon.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2635"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cryptogon.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2635"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}