Security Warning: Serious flaw in Debian Linux OpenSSL Package

last updated in Categories Debian Linux, Linux, Security

There is a serious security flaw in Debian openssl – the random number generator in Debian’s openssl package is predictable. As a result, cryptographic key material may be guessable.

=> Package : openssl
=> Vulnerability : predictable random number generator
=> Problem type : remote
=> Debian-specific: yes
=> CVE Id(s) : CVE-2008-0166
=> Checkout description and recommended fix at the following url:

[SECURITY] [DSA 1571-1] New openssl packages fix predictable random number generator

Posted by: Vivek Gite

The author is the creator of nixCraft and a seasoned sysadmin, DevOps engineer, and a trainer for the Linux operating system/Unix shell scripting. Get the latest tutorials on SysAdmin, Linux/Unix and open source topics via RSS/XML feed or weekly email newsletter.

3 comment

  1. Does this security flaw also infect Ubuntu? Or Just Debian? I’m asking since I know Ubuntu is Debian based and I have an Ubuntu Server in my closet.

  2. yes it did affect ubuntu, for a very short time. it was fixed soon after it was found out in 2006. debian type Os’s now uses a much more secure algorithm. much more secure than windows xp. and more secure than vista. PS the time it would take for some one to use this security vulnerability to compromise your system would not be worth it unless you where a business or some one with some money to be made by hacking your system.

    Have a question? Post it on our forum!