Click here to register.
      
irc://irc.freenode.net#webgui

iPhoneGuy: WebGUI is a pile of crap.
rizen: If WebGUI is such a pile of crap, why do you use it?
iPhoneGuy: Because it's the best pile of crap out there.

If this is what people who hate us are saying, imagine what people who love us will say. Come join us on IRC.


     Discuss > WebGUI Dev

The debian openssl/openssh bug

User patspam
Date 5/14/2008 7:00 pm
Views 286
Rating 1    Rate [
|
]
Previous · Next
User Message
patspam
I'm sure everyone has seen this by now, but in case you missed it:

Anyone whose wG server is running any of the following releases based on Debian:
  • Ubuntu 7.04 (Feisty)
  • Ubuntu 7.10 (Gutsy)
  • Ubuntu 8.04 LTS (Hardy)
  • Ubuntu "Intrepid Ibex" (development): libssl <= 0.9.8g-8
  • Debian 4.0 (etch) (see corresponding Debian security advisory)
Need to recreate all cryptographic key material from scratch (howto).

Ouch.

http://taint.org/2008/05/13/153959a.html

Patrick


Back to Top
Rate [
|
]
 
 
patspam
Just a bit more on this, "cryptographic key material" includes any SSL certificates you have generated on debian-based systems.

Thankfully the WRE version of openssl is less than the effected version number (0.9.8c-1) even in the most recent WRE, and probably doesn't contain the debian patch anyway, so I don't think you need to regenerate any SSL certificates you created using the WRE's openssl binary.

Patrick

On Thu, May 15, 2008 at 10:00 AM, <pat@patspam.com> wrote:
patspam wrote:

I'm sure everyone has seen this by now, but in case you missed it:

Anyone whose wG server is running any of the following releases based on Debian:
  • Ubuntu 7.04 (Feisty)
  • Ubuntu 7.10 (Gutsy)
  • Ubuntu 8.04 LTS (Hardy)
  • Ubuntu "Intrepid Ibex" (development): libssl <= 0.9.8g-8
  • Debian 4.0 (etch) (see corresponding Debian security advisory)
Need to recreate all cryptographic key material from scratch (howto).

Ouch.

http://taint.org/2008/05/13/153959a.html

Patrick


http://www.plainblack.com/webgui/dev/discuss/the-debian-openssl/openssh-bug


--

Plain Black&#44; makers of WebGUI
http://plainblack.com




Back to Top
Rate [
|
]
 
 
     Discuss > WebGUI Dev




Smoketest For nightly_2008-07-05 by Visitor - Sat @ 01:46am

Smoketest For nightly_2008-07-04 by Visitor - Fri @ 01:37am

Re: News Addon? by knowmad - Thu @ 06:04pm

Re: News Addon? by bepo - Thu @ 08:54am

Re: News Addon? by bepo - Thu @ 03:35am

Smoketest For nightly_2008-07-03 by Visitor - Thu @ 01:37am

Thingy Reporting (pt 2) by knowmad - Wed @ 05:37pm

Re: News Addon? by knowmad - Wed @ 05:12pm

spell checker and tinymce by elnino - Wed @ 04:50pm

Re: WebGUI works on perl 5.10 by knowmad - Wed @ 04:41pm

Re: how the cost installing WebGUI ?? by baylink - Wed @ 12:19pm

Re: News Addon? by bepo - Wed @ 07:38am

Re: News Addon? by bepo - Wed @ 03:38am