Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Debian: DSA-2309-1 Critical: Remote Threat From DigiNotar Certificates

debian
Calendar Grey September 13, 2011
Scroller Debian
Debian releases patch for openssl as compromised CAcert certificates highlight vulnerabilities. Immediate upgrade advised.
Several fraudulent SSL certificates have been found in the wild issued by the DigiNotar Certificate Authority, obtained through a security compromise of said company

Summary

Several fraudulent SSL certificates have been found in the wild issued
by the DigiNotar Certificate Authority, obtained through a security
compromise of said company. After further updates on this incident, it
has been determined that all of DigiNotar's signing certificates can no
longer be trusted.
Debian, like other software distributors and vendors, has decided to
distrust all of DigiNotar's CAs. In this update, this is done in the
crypto library (a component of the OpenSSL toolkit) by marking such
certificates as revoked.
Any application that uses said component should now reject certificates
signed by DigiNotar. Individual applications may allow users to overrride
the validation failure. However, making exceptions is highly
discouraged and should be carefully verified.

Additionally, a vulnerability has been found in the ECDHE_ECDS cipher
where timing attacks make it easier to determine private keys. The
Common Vulnerabilities and Exposures project identifies it as
CVE-2011-1945.

For the oldstab...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: openssl
CVE ID: CVE-2011-1945

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.