Click here to register.
      
Sprechen Sie WebGUI? Parlez vous WebGUI? Se habla WebGUI? Spreekt u WebGUI?

Do you speak WebGUI? Please help us translate WebGUI into your language.



     Discuss > WebGUI Dev

The debian openssl/openssh bug

User patspam
Date 5/14/2008 7:00 pm
Views 447
Rating 1    Rate [
|
]
Previous · Next
User Message
patspam
I'm sure everyone has seen this by now, but in case you missed it:

Anyone whose wG server is running any of the following releases based on Debian:
  • Ubuntu 7.04 (Feisty)
  • Ubuntu 7.10 (Gutsy)
  • Ubuntu 8.04 LTS (Hardy)
  • Ubuntu "Intrepid Ibex" (development): libssl <= 0.9.8g-8
  • Debian 4.0 (etch) (see corresponding Debian security advisory)
Need to recreate all cryptographic key material from scratch (howto).

Ouch.

http://taint.org/2008/05/13/153959a.html

Patrick


Back to Top
Rate [
|
]
 
 
patspam
Just a bit more on this, "cryptographic key material" includes any SSL certificates you have generated on debian-based systems.

Thankfully the WRE version of openssl is less than the effected version number (0.9.8c-1) even in the most recent WRE, and probably doesn't contain the debian patch anyway, so I don't think you need to regenerate any SSL certificates you created using the WRE's openssl binary.

Patrick

On Thu, May 15, 2008 at 10:00 AM, <pat@patspam.com> wrote:
patspam wrote:

I'm sure everyone has seen this by now, but in case you missed it:

Anyone whose wG server is running any of the following releases based on Debian:
  • Ubuntu 7.04 (Feisty)
  • Ubuntu 7.10 (Gutsy)
  • Ubuntu 8.04 LTS (Hardy)
  • Ubuntu "Intrepid Ibex" (development): libssl <= 0.9.8g-8
  • Debian 4.0 (etch) (see corresponding Debian security advisory)
Need to recreate all cryptographic key material from scratch (howto).

Ouch.

http://taint.org/2008/05/13/153959a.html

Patrick


http://www.plainblack.com/webgui/dev/discuss/the-debian-openssl/openssh-bug


--

Plain Black&#44; makers of WebGUI
http://plainblack.com




Back to Top
Rate [
|
]
 
 
     Discuss > WebGUI Dev




Re: Config File Changes by pwrightson - Fri @ 04:07pm

Re: IRC Logs by koen - Fri @ 02:08pm

Re: IRC Logs by patspam - Fri @ 02:01pm

Re: IRC Logs by koen - Fri @ 01:42pm

Re: How do I find al my submitted RFE's? by bartjol - Fri @ 01:39pm

Re: IRC Logs by kristi - Fri @ 01:27pm

Re: LastModified question by perlDreamer - Fri @ 12:57pm

Re: How do I find al my submitted RFE's? by bartjol - Fri @ 12:11pm

How do I find al my submitted RFE's? by koen - Fri @ 11:23am

Re: IRC Logs by koen - Fri @ 11:20am

IRC Logs by martink - Fri @ 10:51am

Re: cleaning out the wiki by koen - Fri @ 10:44am

Re: shop in 7.5.21 by kristi - Fri @ 09:03am

shop in 7.5.21 by erikms - Fri @ 08:07am