<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Commenti a: Vulnerabilità openssh per Debian GNU/Linux</title>
	<atom:link href="http://www.ivan.agliardi.it/2008/05/15/vulnerabilita-openssh-per-debian-gnulinux/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ivan.agliardi.it/2008/05/15/vulnerabilita-openssh-per-debian-gnulinux/</link>
	<description>Blog personale di Ivan Agliardi con pagine di informatica, linguaggi, idee...</description>
	<lastBuildDate>Tue, 03 Jan 2012 10:49:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Di: Ivan Agliardi</title>
		<link>http://www.ivan.agliardi.it/2008/05/15/vulnerabilita-openssh-per-debian-gnulinux/comment-page-1/#comment-53</link>
		<dc:creator>Ivan Agliardi</dc:creator>
		<pubDate>Sat, 17 May 2008 07:00:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.ivan.agliardi.net/?p=202#comment-53</guid>
		<description>Mi correggo da solo, prima che lo faccia qualcun altro. La segnalazione presa da autorevole portale dedicato ai sysadmin Debian riportava come non Debian specific questo bug. Dopo avere approfondito l&#039;argomento ho scoperto invece che &lt;u&gt;si tratta di un bug assolutamente Debian specific&lt;/u&gt;. La prossima volta attingo direttamente ai DSA.

Ecco il passaggio del DSA in cui si descrive la natura del bug:


Luciano Bello discovered that the random number generator in Debian&#039;s openssl package is predictable.  This is caused by an incorrect Debian-specific change to the openssl package (CVE-2008-0166). As a
result, cryptographic key material may be guessable.

This is a Debian-specific vulnerability which does not affect other operating systems which are not based on Debian.  However, other systems can be indirectly affected if weak keys are imported into them.

It is strongly recommended that all cryptographic key material which has been generated by OpenSSL versions starting with 0.9.8c-1 on Debian systems is recreated from scratch.  Furthermore, all DSA keys ever used on affected Debian systems for signing or authentication purposes should be considered compromised; the Digital Signature Algorithm relies on a secret random value used during signature generation.

&lt;a href=&quot;http://lists.debian.org/debian-security-announce/2008/msg00152.html&quot; rel=&quot;nofollow&quot;&gt;http://lists.debian.org/debian-security-announce/2008/msg00152.html&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Mi correggo da solo, prima che lo faccia qualcun altro. La segnalazione presa da autorevole portale dedicato ai sysadmin Debian riportava come non Debian specific questo bug. Dopo avere approfondito l&#8217;argomento ho scoperto invece che <u>si tratta di un bug assolutamente Debian specific</u>. La prossima volta attingo direttamente ai DSA.</p>
<p>Ecco il passaggio del DSA in cui si descrive la natura del bug:</p>
<p>Luciano Bello discovered that the random number generator in Debian&#8217;s openssl package is predictable.  This is caused by an incorrect Debian-specific change to the openssl package (CVE-2008-0166). As a<br />
result, cryptographic key material may be guessable.</p>
<p>This is a Debian-specific vulnerability which does not affect other operating systems which are not based on Debian.  However, other systems can be indirectly affected if weak keys are imported into them.</p>
<p>It is strongly recommended that all cryptographic key material which has been generated by OpenSSL versions starting with 0.9.8c-1 on Debian systems is recreated from scratch.  Furthermore, all DSA keys ever used on affected Debian systems for signing or authentication purposes should be considered compromised; the Digital Signature Algorithm relies on a secret random value used during signature generation.</p>
<p><a href="http://lists.debian.org/debian-security-announce/2008/msg00152.html" rel="nofollow">http://lists.debian.org/debian-security-announce/2008/msg00152.html</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

