Click here to register.
      
Sprechen Sie WebGUI? Parlez vous WebGUI? Se habla WebGUI? Spreekt u WebGUI?

Do you speak WebGUI? Please help us translate WebGUI into your language.



     WebGUI Dev > The debian openssl/openssh bug

The debian openssl/openssh bug

User patspam
Date 5/14/2008 7:00 pm
Views 353
Rating 1    Rate [
|
]
Previous · Next
User Message
patspam
I'm sure everyone has seen this by now, but in case you missed it:

Anyone whose wG server is running any of the following releases based on Debian:
  • Ubuntu 7.04 (Feisty)
  • Ubuntu 7.10 (Gutsy)
  • Ubuntu 8.04 LTS (Hardy)
  • Ubuntu "Intrepid Ibex" (development): libssl <= 0.9.8g-8
  • Debian 4.0 (etch) (see corresponding Debian security advisory)
Need to recreate all cryptographic key material from scratch (howto).

Ouch.

http://taint.org/2008/05/13/153959a.html

Patrick


Back to Top
Rate [
|
]
 
 
patspam
Just a bit more on this, "cryptographic key material" includes any SSL certificates you have generated on debian-based systems.

Thankfully the WRE version of openssl is less than the effected version number (0.9.8c-1) even in the most recent WRE, and probably doesn't contain the debian patch anyway, so I don't think you need to regenerate any SSL certificates you created using the WRE's openssl binary.

Patrick

On Thu, May 15, 2008 at 10:00 AM, <pat@patspam.com> wrote:
patspam wrote:

I'm sure everyone has seen this by now, but in case you missed it:

Anyone whose wG server is running any of the following releases based on Debian:
  • Ubuntu 7.04 (Feisty)
  • Ubuntu 7.10 (Gutsy)
  • Ubuntu 8.04 LTS (Hardy)
  • Ubuntu "Intrepid Ibex" (development): libssl <= 0.9.8g-8
  • Debian 4.0 (etch) (see corresponding Debian security advisory)
Need to recreate all cryptographic key material from scratch (howto).

Ouch.

http://taint.org/2008/05/13/153959a.html

Patrick


http://www.plainblack.com/webgui/dev/discuss/the-debian-openssl/openssh-bug


--

Plain Black&#44; makers of WebGUI
http://plainblack.com




Back to Top
Rate [
|
]
 
 

YouSendIt like app. by pvanthony - Sun @ 09:33am

Smoketest For nightly_2008-07-20 by Visitor - Sun @ 01:37am

Smoketest For nightly_2008-07-19 by Visitor - Sat @ 01:38am

Re: Survey2 by perlmonkey2 - Fri @ 05:36pm

Smoketest For nightly_2008-07-18 by Visitor - Fri @ 01:39am

Re: Building WRE for Fedora Core 4 x86_64 by neodymiumex - Thu @ 02:59pm

Tracking file downloads in WebGUI by colink - Thu @ 02:00pm

Smoketest For nightly_2008-07-17 by Visitor - Thu @ 01:39am

Re: Survey2 by perlmonkey2 - Wed @ 11:05pm

Re: Survey2 by patspam - Wed @ 08:05pm

Re: Survey2 by perlmonkey2 - Wed @ 03:41pm

Re: Duplicate web site by techwriter - Wed @ 09:07am

Re: Limiting the size of avatars by bernd - Wed @ 03:45am

Smoketest For nightly_2008-07-16 by Visitor - Wed @ 01:38am

Survey2 by patspam - Tue @ 10:10pm