Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1701-1] New OpenSSL packages fix cryptographic weakness

    From Florian Weimer@1:229/2 to All on Mon Jan 12 21:10:06 2009
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1701-1 [email protected] http://www.debian.org/security/ Florian Weimer January 12, 2009 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : openssl, openssl097
    Vulnerability : interpretation conflict
    Problem type : remote
    Debian-specific: no
    CVE Id(s) : CVE-2008-5077
    Debian Bug : 511196

    It was discovered that OpenSSL does not properly verify DSA signatures
    on X.509 certificates due to an API misuse, potentially leading to the acceptance of incorrect X.509 certificates as genuine (CVE-2008-5077).

    For the stable distribution (etch), this problem has been fixed in
    version 0.9.8c-4etch4 of the openssl package, and version
    0.9.7k-3.1etch2 of the openssl097 package.

    For the unstable distribution (sid), this problem has been fixed in
    version 0.9.8g-15.

    The testing distribution (lenny) will be fixed soon.

    We recommend that you upgrade your OpenSSL packages.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/o/openssl097/openssl097_0.9.7k-3.1etch2.dsc
    Size/MD5 checksum: 1069 fb69818a28ead5b3026dcafc1f5e92d5
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c.orig.tar.gz
    Size/MD5 checksum: 3313857 78454bec556bcb4c45129428a766c886
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4.diff.gz
    Size/MD5 checksum: 56230 ad913155fe55d659741976a1be02ee48
    http://security.debian.org/pool/updates/main/o/openssl097/openssl097_0.9.7k.orig.tar.gz
    Size/MD5 checksum: 3292692 be6bba1d67b26eabb48cf1774925416f
    http://security.debian.org/pool/updates/main/o/openssl097/openssl097_0.9.7k-3.1etch2.diff.gz
    Size/MD5 checksum: 34518 845a986c8a5170953c1e88c2d9965176
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4.dsc
    Size/MD5 checksum: 1107 fd0b477d237c473e3f1491e8821b155d

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.8c-4etch4_alpha.deb
    Size/MD5 checksum: 2561904 e0499757c84819b0cb4919de45e733c4
    http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7-dbg_0.9.7k-3.1etch2_alpha.deb
    Size/MD5 checksum: 3822008 a63ea4834f1be21cf7dacd7a60817914
    http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7_0.9.7k-3.1etch2_alpha.deb
    Size/MD5 checksum: 2209796 1d008a2d9fcb466c0e1393fd6cf1dced
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8-dbg_0.9.8c-4etch4_alpha.deb
    Size/MD5 checksum: 4558410 af0dcd956ae91457c01c5152bea8c775
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4_alpha.deb
    Size/MD5 checksum: 1026098 957ee2ef34a7aa24c41903eea6d1db51
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8_0.9.8c-4etch4_alpha.deb
    Size/MD5 checksum: 2621108 d42a2d70f27723a8dc9aab1dfb83ad10
    http://security.debian.org/pool/updates/main/o/openssl/libcrypto0.9.8-udeb_0.9.8c-4etch4_alpha.udeb
    Size/MD5 checksum: 677162 039dd8968e77f09312fc4e502601b6fe

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8_0.9.8c-4etch4_amd64.deb
    Size/MD5 checksum: 891116 0d771317a58430e6ecea1e38e6889ef4
    http://security.debian.org/pool/updates/main/o/openssl/libcrypto0.9.8-udeb_0.9.8c-4etch4_amd64.udeb
    Size/MD5 checksum: 580208 f08c5d2e4649dd9f077b440d3cd35963
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8-dbg_0.9.8c-4etch4_amd64.deb
    Size/MD5 checksum: 1655264 ec946f04aa2fae3a001be8c7ae330839
    http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7_0.9.7k-3.1etch2_amd64.deb
    Size/MD5 checksum: 753788 e5521b844646e69b1b8f2daa872b83b8
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4_amd64.deb
    Size/MD5 checksum: 992378 417077b8de5a56b9dad0667f2ab5b6e2
    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.8c-4etch4_amd64.deb
    Size/MD5 checksum: 2178820 effca1afcd65d7e418f3cb75dd875b1d
    http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7-dbg_0.9.7k-3.1etch2_amd64.deb
    Size/MD5 checksum: 1326428 670a34f7c39343a7939ba43c4658821c

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8-dbg_0.9.8c-4etch4_hppa.deb
    Size/MD5 checksum: 1586088 66b4b504f0e67fc74c9a98e1f6e8cbac
    http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7-dbg_0.9.7k-3.1etch2_hppa.deb
    Size/MD5 checksum: 1274896 2dc2191758d272e05461f574bd50031b
    http://security.debian.org/pool/updates/main/o/openssl/openssl_0.9.8c-4etch4_hppa.deb
    Size/MD5 checksum: 1030994 cfe12740f5f0492a05646851dc042ba8
    http://security.debian.org/pool/updates/main/o/openssl/libssl0.9.8_0.9.8c-4etch4_hppa.deb
    Size/MD5 checksum: 945354 e001f9834b3a7fbfd69963118afc7922
    http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7_0.9.7k-3.1etch2_hppa.deb
    Size/MD5 checksum: 793836 489e8472b5b300e2627cd25be399f42f
    http://security.debian.org/pool/updates/main/o/openssl/libcrypto0.9.8-udeb_0.9.8c-4etch4_hppa.udeb
    Size/MD5 checksum: 631120 18fb83375c2b5a6689703c1219ad4f65
    http://security.debian.org/pool/updates/main/o/openssl/libssl-dev_0.9.8c-4etch4_hppa.deb
    Size/MD5 checksum: 2248436 0c045e8c6dcc0ee3e89d1808b3818eed

    i386 architecture (Intel ia32)

    http://security.debian.org/pool/updates/main/o/openssl097/libssl0.9.7_0.9.7k-3.1etch2_i386.deb

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 714
    Nodes: 16 (2 / 14)
    Uptime: 141:01:45
    Calls: 12,087
    Files: 14,998
    Messages: 6,517,434

© >>> Magnum BBS <<<, 2026