IT security, vunerabilities, bugs, fixes, flaws, RSA conference and Infosec.
A blog from V3.co.uk

« Cyber bullying a common problem | Main | New botnet appears »

Security experts confirm Linux vulnerability

Security experts have confirmed a suspected vulnerability in the Debian and Ubuntu Linux operating systems.

Application vulnerability specialist Fortify Software confirmed the findings of a research posting to the Debian security list last week, which details a critical security vulnerability in the OpenSSL packages within Debian and Ubuntu.

Fredrick Lee, a researcher with Fortify, said that the posting actually understates the potential seriousness of the flaw, which affects the Open Secure Sockets Layer.

"We're calling this vulnerability `insecure randomness' since it allows an attacker to predict the SSL cryptographic keys used for supposedly secure online transactions," he said.

May 20, 2008 |

Comments

Post a comment







Site credentials: About | Privacy policy | Terms & conditions | Top of the page
© Incisive Media Investments Limited 2010, Published by Incisive Financial Publishing Limited, Haymarket House, 28-29 Haymarket, London SW1Y 4RX, are companies registered in England and Wales with company registration numbers 04252091 & 04252093