Company
Date Published
Author
Tom Preston-Werner
Word count
195
Language
English
Hacker News points
None

Summary

A security alert issued on the Debian security list highlights a vulnerability in the OpenSSL package on Debian-based systems, including Ubuntu, where the random number generator is highly predictable due to a specific change, identified as CVE-2008-0166. This issue, discovered by Luciano Bello, could lead to cryptographic keys being guessable and poses a Debian-specific threat, although other systems could be indirectly affected if weak keys are imported. It is advised that all cryptographic key material generated by affected versions of OpenSSL, starting with 0.9.8c-1, be recreated, and any DSA keys used on affected systems should be considered compromised due to their reliance on a secret random value. Users are urged to discontinue the use of compromised keys and update their GitHub keys after patching their Debian-based systems.