his wholiness the rev drjon ([info]drjon) wrote,
@ 2008-05-15 09:55:00
Previous Entry  Add to memories!  Tell a Friend!  Next Entry
Ubuntu/Debian Update Urgent
news from [info]theweaselking
http://metasploit.com/users/hdm/tools/debian-openssl/
If you have a Debian or Ubuntu system, update *now* and delete all SSH and SSL certificates and keys you generated before the update. Generate new ones, unless you installed openssh TODAY.

For Ubuntu, this affects 7.04+. 6.06 is safe. For Debian, fcuked if I know. Debian is obsolete, pretty much by definition.
I half-expect anyone running Ubuntu will already be in on the loop with this.

If this was a Windows hole, you wouldn't even be hearing about it until August, when MS finally rolled out the fix.


(Post a new comment)


[info]sjl
2008-05-15 12:59 pm UTC (link)
If this was a Windows hole ...

MS would roll out the fix quietly, and not tell their users that they needed to regenerate their keys.

Debian screwed up, 'tis true. But at least they screwed up publicly.</a>

(Reply to this)


[info]ser_kai
2008-05-15 02:27 pm UTC (link)
Thanks for the heads up. Fuck. I guess I don't need sleep after all.

(Reply to this)


Create an Account
Forgot your login?
Login w/ OpenID
English • Español • Deutsch • Русский…