[maemo-developers] OpenSSH vulnerability and maemo extras upload accounts.

From: Niels Breet niels at maemo.org
Date: Fri May 16 23:06:40 EEST 2008
Hi,

Recently a security issue has been found in Debian\'s implementation
of OpenSSH as per CVE-2008-0166.

That directly affects openssh, and any key generated on Debian or
Debian-derived systems from then until the recent security updates (on
Debian, versions 0.9.8c-4etch3 or 0.9.8g-9) is deemed potentially
compromised.

We have mailed and disabled the keys for all people believed to have a
compromised key, but it is possible that we didn't detect every key.

If you have uploaded your key to garage.maemo.org and you believe this
affects you: Please update your own version of OpenSSH and
after that please re-generate a ssh key.

You can replace your ssh key here:
https://garage.maemo.org/account/index2.php

If you have any questions, please feel free to contact me.

We are sorry for the inconvenience caused by this.

--
Niels Breet
maemo.org webmaster




More information about the maemo-developers mailing list