File APIs for Java Developers
Manipulate DOC, XLS, PPT, PDF and many others from your application.
The moose likes Security and the fly likes Debian/Ubuntu ssh weakness found Big Moose Saloon
  Search | Java FAQ | Recent Topics | Flagged Topics | Hot Topics | Zero Replies
Register / Login
JavaRanch » Java Forums » Engineering » Security
Bookmark "Debian/Ubuntu ssh weakness found" Watch "Debian/Ubuntu ssh weakness found" New topic

Debian/Ubuntu ssh weakness found

Pat Farrell

Joined: Aug 11, 2007
Posts: 4659

There is a security patch out today for Debian, ubuntu, and all other distros based on debian.

In short someone 'fixed' the random number generator in the key generation code in the debian version, and did not send the patch up to the openSSL folks. The patch was bad.

This is an example of why crypto is serious, it can look fine and be used for years.
Ulf Dittmer

Joined: Mar 22, 2005
Posts: 42965
Somewhat related to the topic of open source security, a couple of links that may be of wider interest:
  • - advisories about open source vulnerabilities
  • Discussion on Is Open Source Good for Security?
    I agree. Here's the link:
    subject: Debian/Ubuntu ssh weakness found
    It's not a secret anymore!