<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Resource &#187; Debian</title>
	<atom:link href="http://www.itresource.com.au/category/linux/debian/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.itresource.com.au</link>
	<description>Your one stop Information Technology Resource</description>
	<lastBuildDate>Sun, 23 May 2010 03:53:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Debian, Ubuntu Flawed For Two Years</title>
		<link>http://www.itresource.com.au/2008/05/21/debian-ubuntu-flawed-for-two-years/</link>
		<comments>http://www.itresource.com.au/2008/05/21/debian-ubuntu-flawed-for-two-years/#comments</comments>
		<pubDate>Wed, 21 May 2008 11:34:37 +0000</pubDate>
		<dc:creator>Dave W</dc:creator>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Ubuntu]]></category>

		<guid isPermaLink="false">http://www.itresource.com.au/?p=364</guid>
		<description><![CDATA[A research posting to the Debian security list last week has led to the confirmation of a serious hole in two flavours of the Open Source Linux operating system. Frederick Lee, a researcher at insecurity company Fortify, said that the flaw, which affects Ubuntu as well as Debian, had been &#8220;seriously underestimated &#8221; as it [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.itresource.com.au/wp-content/uploads/2008/05/tux.gif" alt="Tux" class="alignleft" style="float: left;" />A research posting to the Debian security list last week has led to the confirmation of a serious hole in two flavours of the Open Source Linux operating system.</p>
<p>Frederick Lee, a researcher at insecurity company Fortify, said that the flaw, which affects Ubuntu as well as Debian, had been &#8220;seriously underestimated &#8221; as it makes the Secure Sockets Layer (SSL) of the two Linux sustems vulnerable to malicious attack.</p>
<p>&#8220;We&#8217;re calling this vulnerability &#8216;insecure randomness&#8217; since it allows an attacker to predict the SSL cryptographic keys used for supposedly secure online transactions,&#8221; he said.</p>
<p>Lee reckons that the flaw, which tinkers with the randomness engine used to encrypt secure transactions, could be used to intercept traffic between a user and supposedly secure connection between a user and, for example, an online banking site.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itresource.com.au/2008/05/21/debian-ubuntu-flawed-for-two-years/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenSSL Bug Found in Debian Linux</title>
		<link>http://www.itresource.com.au/2008/05/16/openssl-bug-found-in-debian-linux/</link>
		<comments>http://www.itresource.com.au/2008/05/16/openssl-bug-found-in-debian-linux/#comments</comments>
		<pubDate>Fri, 16 May 2008 00:23:30 +0000</pubDate>
		<dc:creator>Dave W</dc:creator>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.itresource.com.au/?p=343</guid>
		<description><![CDATA[Debian Linux got a bit of a black eye this week with the announcement that a nasty cryptographic vulnerability exists in its version of the OpenSSL package. Debian, especially its stable branch, is widely regarded as perhaps the most bulletproof Linux distribution. Debian also has the not undeserved reputation of being difficult for those new [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.itresource.com.au/wp-content/uploads/2008/05/tux.gif" alt="Lunux Tux" class="alignleft" style="float: left;" />Debian Linux got a bit of a black eye this week with the announcement that a nasty cryptographic vulnerability exists in its version of the OpenSSL package.</p>
<p>Debian, especially its stable branch, is widely regarded as perhaps the most bulletproof Linux distribution.</p>
<p>Debian also has the not undeserved reputation of being difficult for those new to Linux to install and manage.</p>
<p>The Debian maintainers apparently created the vulnerability by deleting code that seeded the random number generation used to calculate encryption keys.<br />
<span id="more-343"></span><br />
The result was that the random number generator used in Debian&#8217;s OpenSSL package was predictable, leading to cryptographic keys that might guessable.</p>
<p>Debian Security Advisory DSA-1571-1 states: &#8220;Affected keys include SSH keys, OpenVPN keys, DNSSEC keys, and key material for use in X.509 certificates and session keys used in SSL/TLS connections. Keys generated with GnuPG or GNUTLS are not affected, though.&#8221;</p>
<p>The advisory also publishes the URLs for a detector of weak encryption keys, as well as the location of instructions about how to implement key rollover.</p>
<p>The vulnerability only exists in Debian and Debian derived Linux systems, but those also include the Ubuntu versions of Linux that have lately become quite popular among casual desktop Linux users.</p>
<p>The problematic OpenSSL code appeared in the Debian unstable distribution on September 17, 2006 and has since been propagated into the current stable and testing distributions named Etch. The previous stable Debian distribution named Sarge is not affected.</p>
<p>Many Debian Linux desktop users shouldn&#8217;t be affected by this Secure Sockets Layer (SSL) bug unless they&#8217;ve generated cryptographic keys for Secure Shell (SSH) access between systems or digital signing or authentication certificates.</p>
<p>However, techies who administrate Debian based Linux systems that traffic in certificates might be scurrying about somewhat in coming days as they apt-get the upgraded OpenSSL package and regenerate and roll over cryptographic keys and certificates.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itresource.com.au/2008/05/16/openssl-bug-found-in-debian-linux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

