republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Tech and Talk » OS and Software » All Things Unix » Heads Up: Debian OpenSSL RNG Vuln CVE-2008-0166
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Gentoo revokes developer rights of 3, Cabal suspected. »
« Which is more stable and reliable UNIX OS?  
AuthorAll Replies


BeesTea
Network Janitor
Premium,VIP
join:2003-03-08
00000

reply to evilghost
Re: Heads Up: Debian OpenSSL RNG Vuln CVE-2008-0166

For sure host keys would be vulnerable too. The public/private key exchange to build an ssh session pre-auth is almost identical to the one used for auth.

It's going to be a while before all the impact of this is fully understood I think. Thanks for pointing that out. It might be worth brain dumping all the places where SSL might get used like that.
--
Overpower, overcome.
Forums » Tech and Talk » OS and Software » All Things UnixGentoo revokes developer rights of 3, Cabal suspected. »
« Which is more stable and reliable UNIX OS?  


Friday, 04-Dec 14:21:04 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [145] Avast Antivirus Has Gone Mad
· [117] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [99] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [76] FCC Ponders Moving From PSTN To IP Voice
· [74] Sprint Defuses GPS Privacy Media Bomb
· [70] Baltimore To Ban Lazy Cable Installs
· [64] Broadband Killed The Game Console
Most people now reading
· False positive in Avast! or is it real? [Security]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· People would bewalking away from the table if ACTA public [TekSavvy]
· [WotLK] Doing away w/ conquest? [World of Warcraft]
· DNS options, what are YOU using? [TekSavvy]
· [Rant] Disrespect of PTO [Rants, Raves, and Praise]
· Am I the only one that loves to work in IT? [No, I Will Not Fix Your #@$!! Computer]
· Linux is terrorist - according to MS... [All Things Unix]
· Maximizing Rogue DPS for ToC/ToGC (3.x) [World of Warcraft]
· LFM Overkill [World of Warcraft]