Tuesday, May 13, 2008

Serious security vulnerability in Debian, Ubuntu SSH package

Serious security vulnerability in Debian, Ubuntu SSH package

Yikes. Now’s a good time to run Update Manager. Your key will change, which means you’ll get a scary warning when you next try to login remotely.

Edit: Ubuntu’s package manager will automatically regenerate your machine’s bad SSH key. Debian’s will not. (Just verified myself on both OS’s.) Debian will post instructions here once they get around to writing them.