Bug#454666: MD5 signatures provide no security

2007-12-06 Thread bear
Package: dpkg Version: 1.13.25 Severity: critical Note: reported against the current version of dpkg, but applies equally to all versions up to the present time. MD5 checksums are not secure. A recently discovered mathematical technique allows *ANY* document containing a few attacker-chosen

Processed: Re: Bug#454666: MD5 signatures provide no security

2007-12-06 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: reassign 454666 apt Bug#454666: MD5 signatures provide no security Bug reassigned from package `dpkg' to `apt'. thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking system administrator (administrator

Bug#454666: MD5 signatures provide no security

2007-12-06 Thread Frank Lichtenheld
reassign 454666 apt thanks On Thu, Dec 06, 2007 at 02:33:06PM -0800, [EMAIL PROTECTED] wrote: Exploitation of this flaw would allow an attacker to substitute arbitrary code for any legitimate Debian package using a man in the middle attack undetected whenever a user is installing new

Bug#454666: MD5 signatures provide no security

2007-12-06 Thread Christian Perrier
Quoting Frank Lichtenheld ([EMAIL PROTECTED]): reassign 454666 apt thanks On Thu, Dec 06, 2007 at 02:33:06PM -0800, [EMAIL PROTECTED] wrote: Exploitation of this flaw would allow an attacker to substitute arbitrary code for any legitimate Debian package using a man in the middle attack

Bug#454666: MD5 signatures provide no security

2007-12-06 Thread Sam Hocevar
severity 454666 normal thanks On Thu, Dec 06, 2007, [EMAIL PROTECTED] wrote: In particular, it is now computationally feasible for a single attacker with a desktop machine to modify any executable of his or her choosing to have any desired MD5 checksum. Ray, Debian is not Slashdot. I