Debian Security Flaw
The debian security flaw and the supposed attacks were pointed out to me earlier today. There's a blurb about it here on LJ. The US-CERT warning is here. The original debian advisory about the actual bug is here. I say "supposed attacks" cuz if the government says it, I'm skeptical, but that's another can of worms...
Instead of just rehashing what the security advisory says and what evvvverrrrybody else has already said I thought I'd see if I could actually see what the original patch was. Well that didn't really work out, I downloaded the patch referenced from the debian advisory page and took a look at it, but it's got numerous other fixes included and this specific fix was not obvious.
The last changelog entry is:
+openssl (0.9.8c-4etch3) stable-security; urgency=high + + * Re-introducing seeding of the random number generator. Patch from the + maintainer. + + -- .... <....@...> Thu, 08 May 2008 01:58:40 +0200Which based on what I understand about the problem sounds like the culprit. It's also the only entry with about the right date.
So with that I went to the debian subversion repository to see if I could look at the isolated change, without all the other changes. Well, that didn't work out too well either because it doesn't appear to me that the change was ever committed to the repository. Of course, I suspect it has or there's a good reason why it isn't there and I'm just missing something, but it would be nice if somebody could confirm that everything's ok.
Mitch Frazier is an Associate Editor for Linux Journal.
One Click, Universal Protection: Implementing Centralized Security Policies on Linux Systems
Join editor Bill Childers and Bit9's Paul Riegle on April 27 at 12pm Central to learn how to keep your Linux systems secure.
Free to Linux Journal readers.Register Now!
- Cluetrain at Fifteen
- Embedding Python in Your C Programs
- Getting Good Vibrations with Linux
- New Products
- Memory Ordering in Modern Microprocessors, Part I
- Customizing Vim
- [<Megashare>] Watch Mrs Brown's Boys Movie Online Full Movie HD 2014
- Security Hardening with Ansible
- Tech Tip: Really Simple HTTP Server with Python
- RSS Feeds