Re: OpenSSH vulnerability (Ubuntu and Debian hit)

Top Page
Attachments:
Message as email
+ (text/plain)
Delete this message
Reply to this message
Author: Anthony Boynes
Date:  
To: Main PLUG discussion list
Subject: Re: OpenSSH vulnerability (Ubuntu and Debian hit)
These urls should also be looked at.

http://www.ubuntu.com/usn/usn-612-2
http://www.debian.org/security/2008/dsa-1571

On Tue, May 13, 2008 at 10:37 AM, Carlos Macedo Gomes
<> wrote:
> Apologies if this has already vectored through your radar. A problem
> has surfaced with Debian and Ubuntu related to the PRN in OpenSSL (and
> therefore the keys in OpenSSH, OpenSSL, SSL, etc). Scope is limited
> to Debian and Ubuntu systems but the problem appears to have been
> around for a couple years.
>
> Ubuntu advisory is here:
> http://www.ubuntu.com/usn/usn-612-1
>
> Here's a (rantish) writeup on the *raison d'etre*:
> http://www.links.org/?p=327
>
> Check your primes...
>
> ymmv,
> C.G.
>
> --
>
> Carlos Macedo Gomes
> _sic itur ad astra_
> ---------------------------------------------------
> PLUG-discuss mailing list -
> To subscribe, unsubscribe, or to change your mail settings:
> http://lists.PLUG.phoenix.az.us/mailman/listinfo/plug-discuss
>

---------------------------------------------------
PLUG-discuss mailing list -
To subscribe, unsubscribe, or to change your mail settings:
http://lists.PLUG.phoenix.az.us/mailman/listinfo/plug-discuss