Urgent Ubuntu security notice
Posted at 15:45:10
on Tue, May 13th 2008 by graham
in:
in the news
security
ubuntu
This will only apply to Ubuntu users (server or desktop). Anyone who's not one can probably look away now.
An urgent Ubuntu Security Notice, USN-612-1, has just been put out. The full notice is here.
An extract of the salient details:
A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH, OpenVPN and SSL certificates.
So, update and upgrade your systems now and regenerate your key pairs.

