aboutsummaryrefslogtreecommitdiff
path: root/debian/tor.NEWS
blob: 18860ccaae43ffbb8534702c5ab52af0801f233f (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
tor (0.2.0.26-rc-1) experimental; urgency=critical

  * weak cryptographic keys

    It has been discovered that the random number generator in Debian's
    openssl package is predictable.  This is caused by an incorrect
    Debian-specific change to the openssl package (CVE-2008-0166).  As a
    result, cryptographic key material may be guessable.

    See Debian Security Advisory number 1571 (DSA-1571) for more information:
    http://lists.debian.org/debian-security-announce/2008/msg00152.html

    If you run a Tor server using this package please see
    /var/lib/tor/keys/moved-away-by-tor-package/README.REALLY

 -- Peter Palfrader <weasel@debian.org>  Tue, 13 May 2008 12:49:05 +0200