Most Popular in Linux
-
Tizen 1.0 hands-on: Can Samsung and Intel?s mobile OS compete with Android?
-
Two EA Games Arrive in Ubuntu 12.04 LTS
-
Obama calls Romney auto bailout claim an 'Etch-a-Sketch moment'
-
Olympia torch lighting starts London countdown
-
Fedora Project is naming names
-
Moderate Taliban says majority of group wants peace
-
How to Sync Files to Amazon S3 on Linux
-
Development Release: GNOME 4.0 Beta
-
Romney faces lengthy to-do list as likely GOP pick
-
Linux Users Beware: Patch New Samba Flaw 'Immediately'
[$] A hole in crypt_blowfish
A longstanding bug that was recently found in the crypt_blowfish password hashing
library highlights
the problems that can occur when a bug is found in a widely used low-level
library. Because crypt_blowfish has been around for so long
(this bug is said to go back to 1998 or possibly 1997), it has been used by
various other packages (PHP for example) as well as some Linux
distributions. The security impact is not likely to be huge, because it
only affects passwords with somewhat uncommon characteristics, but the
impact on those who have stored hashed passwords generated using the
library may be a bit more painful. Subscribers can click below for a look
at the bug from this week's Security page.
More Stories in Linux Weekly News
- Stable kernels 3.0.32 and 3.3.7
- Nmap 6 released
- Linux kernel 3.2.18 released
- The Russians Are Coming: A First Look At Rosa 2012 Marathon (O'Reilly)
- Perl 5.16.0 released
- The 3.4 kernel is out
- X.Org: "A Wasteland of Unreviewedness" (Phoronix)
- A scientific basis for Open Source Software
- Security advisories for Friday
- Fedora 17 release pushed back to May 29
Most Popular Stories
A fix for those "Pairing Record Missing" errors
Splitting the file
AIX KSH: 0403-029 There is not enough memory available now
AIRbudz: A safer way to listen to your tunes
sed substitution for specific record
You're the Pundit: Are we going to see form factor changes?
Earthlapse is a window on the Earth from space
Rumored three iPad model lineup could cut entry price to $299
sendmail long text
Howto Convert a filesystem from Veritas to ZFS?