Debian SSH keys insecure! Ubuntu also affected!

Posted by Anshu Prateek as linux, network, news, security bug


http://lists.debian.org/debian-security-announce/2008/msg00152.html
A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. […]

Popularity: 5%