Turns out there is an OpenSSH update for Ubuntu 6.06 LTS

| | Comments (0) |

Thanks go out to commenter pcfixitguy for telling me about the update to the OpenSSH-server packages in Ubuntu 6.06 LTS.

While I'm here, I might as well quote the full text of the security advisory (emphasis mine):

===========================================================

Ubuntu Security Notice USN-612-7 May 20, 2008 openssh update CVE-2008-0166 ===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:

Ubuntu 6.06 LTS:

openssh-server 1:4.2p1-7ubuntu3.4

In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

USN-612-2 introduced protections for OpenSSH, related to the OpenSSL vulnerabilities addressed by USN-612-1. This update provides the corresponding updates for OpenSSH in Ubuntu 6.06 LTS. While the OpenSSL in Ubuntu 6.06 is not vulnerable, this update will block weak keys generated on systems that may have been affected themselves.

Original advisory details:

A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH, OpenVPN and SSL certificates.
The reason I missed it is because I don't have OpenSSH-server installed in Ubuntu 6.06 LTS.

Once again, I'm glad this serious vulnerability is being fixed throughout the Debian-derived world, but the fact that the security issue lingered for two years remains very, very troubling.

Leave a comment

Tech Talk column

Steven Rosenberg's weekly Tech Talk column, which appears Saturdays in the Los Angeles Daily News, is now available on the Daily News Technology page.

About this blog

Comments are back: Comments have returned to Click, but due to the thousands of spam comments clogging up the system each day, commenters must now log in. To comment, either create a Movable Type account when prompted, or create and use a Typekey account. Movable Type, as configured on this blog, allows commenters to create a Movable Type account, verify it via e-mail and then sign in to comment. Other methods of verification are OpenID, Live Journal and Vox.




Steven Rosenberg aims to learn what he does not know. He writes about it here.



About this Entry

This page contains a single entry by Steven Rosenberg published on May 20, 2008 2:00 PM.

I want to upgrade from OpenBSD 4.2 to 4.3, but I'm wary was the previous entry in this blog.

I did the OpenBSD 4.2 to 4.3 upgrade is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Recent Comments

Powered by Movable Type 4.21-en

Advertisement

Other blogs

About The Run Defense in Inside USC with Scott Wolf
HS FOOT: Taft up 16-0 after three quarters in Daily News High School Spotlight
Halftime: Lakers 50, Suns 44 in Inside the Lakers
Elton Brand saga Part I in Inside the Clippers
Kings vs. Capitals in Inside the Kings