Ubuntu
Ubuntu is among the affected Linux distributions

Critical Linux vulnerability exposed

Debian and Ubuntu affected by 'insecure randomness' flaw

Clement James

Security experts have warned of a suspected vulnerability in the Debian and Ubuntu Linux operating systems.

Fortify Software confirmed the findings of a posting to the Debian security list last week, which detailed a critical vulnerability in the Open Secure Sockets Layer (SSL) packages within Debian and Ubuntu.

Advertisement

Fredrick Lee, a researcher at Fortify, claimed that the posting actually understates the potential seriousness of the flaw.

"We are calling this vulnerability 'insecure randomness' since it allows an attacker to predict the SSL cryptographic keys used for supposedly secure online transactions," he said.

Lee explained that a malicious user could intercept an ostensibly secure online banking session between a customer and their bank.

"What's worse is that our researchers calculate this flaw has been available to hackers for more than two years," he said.

This flaw has been available to hackers for more than two years

Fredrick Lee Fortify Software

The problem stems from a bug fix issued by Debian programmers that effectively "emasculates" the randomness engine required to ensure true security within the SSL module.

"Had we been contacted as part of the release strategy, as a number of other developers do, the flaw would have been immediately identified by our research team before the insecure update was released to the public," said Lee.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Linux

Open source security improving rapidly

Two-year quality analysis studied 250 popular applications

One Laptop per Child

OLPC Sugar software goes independent

Walter Bender launches Sugar Labs

Asus to offer Linux on all motherboards

Taiwanese manufacturer will embed open source OS across entire range

OpenSuse joins Google Summer of Code

Novell-sponsored open source project gets 10 slots

Related whitepapers

Related jobs

Most watched

HTC Hero

Video: HTC Hero launch

Handset maker unveils its latest Android-based smartphone

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Twitter

Twitter charges are bad idea, say V3.co.uk readers

Over a third insist the service should remain free for...

great wall of china

Podcast Special: Views from the Valley

The hottest stories from the US, including news of China's...

Mobile phone charger

Top 10 articles, 3 July 09

Free upgrades for Windows 7, and standard mobile phone chargers...

Red Hat

Red Hat beta builds on virtualisation plans

Kernel-based Virtual Machine virtualisation added to latest Enterprise Linux beta

Primary Navigation