As per Red Hat newsletter, the system used by the Fedora Project to sign the software packages for automatically updating end users’ systems has been breached, the attack on network also affected the Fedora Project’s database and proxy servers, hosted systems and collaboration network.Fedora Project claimed that the intruders did not get the package signing key, the encryption master key with which attackers could inject malicious codes into Fedora users’ systems through the update process.
Though the intruder was able to sign a small number of OpenSSH packages relating only to Red Hat Enterprise Linux 4 (i386 and x86_64 architectures only) and Red Hat Enterprise Linux 5 (x86_64 architecture only), as a precautionary measure, Red Hat has release an updated version of compromised packages and have published a list of the tampered packages and how to detect them.
Networks with critical Red Hat Servers are advised to verify their server packages.
You may also like this
- No Related Post
Read the original here:
Red Hat, Fedora Project Network Compromised.
0 comments:
Post a Comment