Welcome to P2PNET.net - The original daily p2p and digital news site. Always First!
Register | Login
RIAA News
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
TV
Open Source
Mobiles
Advertising
Product News
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
Kids and Kartels
Search: 
Search
 
Web P2PNET   
Search: 
Search
Torrent Site Tracker
MP3Rocket
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code

Debian Linux ‘Major security flaw’

p2pnet news | Open Source:- Debian GNU/Linux’s implementation of the Secure Sockets Layer communications protocol “made it easy for attackers to discover encryption keys,” says the Gartner group.

Debian uses the open source OpenSSL version of Secure Sockets Layer and the ‘glitch’ was caused by Debian developers implementing, “changes to OpenSSL to fix a memory leak without first consulting the OpenSSL development community,” states InformationWeek.

“The Debian ‘fix’ resulted in a serious weakness in the OpenSSL random number generator,” according to the researchers, says the story, going on:

“Gartner said the Debian organization was unresponsive to its attempts to contact it about the issue,” but, “Debian has issued a patch to fix the problem,” says the story, adding Gartner is advising businesses which use Debian GNU/Linux, “to implement the patch and regenerate all cryptographic keys generated by Debian OpenSSL versions beginning with 0.9.8c-1″.

.Add to Technorati Favorites .Stumble It!

InformationWeek – Debian Linux Suffers From ‘Major Security Flaw,’ Gartner Warns , May 28, 2008


Use free p2pnet newsfeeds for your site. It’s really easy!

Subscribe
to p2pnet.net
| |
rss feed: http://p2pnet.net/p2p.rss | | Mobile – http://p2pnet.net/index-wml.php


Net access blocked by government restrictions? Use Psiphon from the Citizen Lab at the University of Toronto. Go here for details. Download here.

HOME

2 Responses to “Debian Linux ‘Major security flaw’”

  1. Reader's Write Says:

    This happens several times a week with microsoft/apple (and they take longer to relese patches)

    But it dose highlight why you should not use automated code security tools which fixed the code by removing randomness when it was actually needed.

    It also shows that you should pass code patches up the chain as this would have caught the problem and after the real ssl team had a good lol moment seeing this patch they would have told the author of this patch why.

  2. Reader's Write Says:

    old, very old…

Leave a Reply

Please no Spam, flaming (attacking others), trolling, and posting off-topic. Thanks.

    Advertisements
TekSavvy


Remove Spyware with AntiSpyware for Windows®