ssh-vulnkey needs to be backported to Ubuntu 6.06 LTS

Bug #231047 reported by Zach
256
Affects Status Importance Assigned to Milestone
openssh (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Vulnerable ssh keys expose systems to attack that don't have the openssl PRNG vulnerability. The vulnerable key scanning tools such as ssh-vulnkey need to be backported to supported releases.

Futher, it would be helpful to make a statically compiled version downloadable via http so non debian/ubuntu administrators can scan their systems' authorized_keys and other files for vulnerable keys introduced by debian/ubuntu users.

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for using Ubuntu and taking the time to report a bug. This was fixed in http://www.ubuntu.com/usn/usn-612-7.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.