Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian DSA-1888-1 Critical: OpenSSL MD2 Hash Signature Exclusion

debian
Calendar Grey September 15, 2009
Debian Logo
OpenSSL has discontinued support for MD2 signed certificates due to major vulnerabilities. Updating your OpenSSL libraries is essential for better security and threat protection
Certificates with MD2 hash signatures are no longer accepted by OpenSSL, since they're no longer considered cryptographically secure

Summary

Certificates with MD2 hash signatures are no longer accepted by OpenSSL,
since they're no longer considered cryptographically secure.

For the stable distribution (lenny), this problem has been fixed in
version 0.9.8g-15+lenny5.

For the old stable distribution (etch), this problem has been fixed in
version 0.9.8c-4etch9 for openssl and version 0.9.7k-3.1etch5 for
openssl097.
The OpenSSL 0.9.8 update for oldstable (etch) also provides updated
packages for multiple denial of service vulnerabilities in the
Datagram Transport Layer Security implementation. These fixes were
already provided for Debian stable (Lenny) in a previous point
update. The OpenSSL 0.9.7 package from oldstable (Etch) is not
affected. (CVE-2009-1377, CVE-2009-1378, CVE-2009-1379,
CVE-2009-1386 and CVE-2009-1387)

For the unstable distribution (sid), this problem has been fixed in
version 0.9.8k-5.

We recommend that you upgrade your openssl packages.

Upgrade instructions
- --------------------

wget url
will fetch the file for you
...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: openssl, openssl097

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here