Archive

Archive for the ‘Debian’ Category

Debian, Ubuntu Flawed For Two Years

May 21st, 2008 Dave W No comments

TuxA research posting to the Debian security list last week has led to the confirmation of a serious hole in two flavours of the Open Source Linux operating system.

Frederick Lee, a researcher at insecurity company Fortify, said that the flaw, which affects Ubuntu as well as Debian, had been “seriously underestimated ” as it makes the Secure Sockets Layer (SSL) of the two Linux sustems vulnerable to malicious attack.

“We’re calling this vulnerability ‘insecure randomness’ since it allows an attacker to predict the SSL cryptographic keys used for supposedly secure online transactions,” he said.

Lee reckons that the flaw, which tinkers with the randomness engine used to encrypt secure transactions, could be used to intercept traffic between a user and supposedly secure connection between a user and, for example, an online banking site.

Categories: Debian, Linux, News, Security, Ubuntu Tags:

OpenSSL Bug Found in Debian Linux

May 16th, 2008 Dave W No comments

Lunux TuxDebian Linux got a bit of a black eye this week with the announcement that a nasty cryptographic vulnerability exists in its version of the OpenSSL package.

Debian, especially its stable branch, is widely regarded as perhaps the most bulletproof Linux distribution.

Debian also has the not undeserved reputation of being difficult for those new to Linux to install and manage.

The Debian maintainers apparently created the vulnerability by deleting code that seeded the random number generation used to calculate encryption keys.
Read more…

Categories: Debian, Linux, News Tags: