Ubuntu/Debian, vulnerability in Openssl
Here ready on a silver plate a beautiful security bug for Debian and derived in openssl. In good substance the generator of accidental numbers in the package debian of opessl is expectable, consequently also the crittografata key can be discovered. Here the data in synthesis:
=> Package: openssl
=> Vulnerability: predictable random number generator
=> Problem type: remote
=> Debian-specific: yes
=> CVE Id (s): CVE-2008-0166
=> Checkout description and recommended fix to here:
To execute a control for the location of keys “weak people”:
# wget http://security.debian.org/project/extra/dowkd/dowkd.pl.gz
# wget http://security.debian.org/project/extra/dowkd/dowkd.pl.gz.asc
# gpg - keyserver subkeys.pgp.net - recv-keys 02D524BE
# gpg - verify dowkd.pl.gz.as c
# gunzip dowkd.pl.gz
# Perl dowkd.pl host localhost
The result would have to be 0. If instead we use Debian or Ubuntu we must supply to a upgrade of openssl that it will carry out “fix” (the repair) of the software vulnerable. In this wiki there is a complete and detailed trattazione of the problem and its solutions.
Source nixCraft.
Post correlated…
Like connecting itself to Internet with: cellular bluetooth gnome ppp by Mad on June 7th, 2008
Till little tiny ones ago I used the cable usb in order to connect the cellular one to the PC and to connect to me to Internet.
First steps with piccolino by the Mad on July 31st, 2008
Now I can fregiarmi of the title skillful it of “detective”, in fact mine “birthday gift” it was effectively splendid eeepc 900 a black one, “piccolino”.
To share rows with NFS is better by Mad on May 10th, 2008
In post the precedence I have tried to explain like sharing rows between two PC linuc with samba.
New 4,1 script in order to compile kde by Mad on June 30th, 2008
From some day it has been released a new version of kdesvn-build, the script in order to compile kde 4.
To install Ubuntu Netbook Remix on Hardy Heron by Mad on June 5th, 2008
Here the guide promised in post the precedence.





















30 June 2008 to the 10:18 am
[...] debian/ubuntu packages. The random number generator in Debian's openssl package is predictable. http://www.tuxmind.org/2008/06/16/ubuntudebian-vulnerabilita-in-openssl/OpenSSL Command-Linen HOWTOThe openssl application that ships with the openssl libraries can perform [...]
10 July 2008 to the 9:23 pm
[...] debian/ubuntu packages. The random number generator in Debian's openssl package is predictable. http://www.tuxmind.org/2008/06/16/ubuntudebian-vulnerabilita-in-openssl/Random NumberASP 101 is the place developers go for Active Serveur Pages and ASP.NET [...]