Daniel Bleichenbacher discovered a flaw in OpenSSL cryptographic package that could allow an attacker to generate a forged signature that OpenSSL will accept as valid. Fixed packages are available from
Debian Security Advisory DSA 1173-1                                       Noah Meyerhans
September 10th, 2006          
Package        : openssl
Problem-Type   : local
Vulnerability  : Cryptographic weakness
Debian-specific: no
CVE ID         : CVE-2006-4339
BugTraq ID     : 19849
Debian Bug     : 386247

Daniel Bleichenbacher discovered a flaw in OpenSSL cryptographic package
that could allow an attacker to generate a forged signature that OpenSSL
will accept as valid.

For the stable distribution (sarge) this problem has been fixed in
version 0.9.7e-3sarge2

For the unstable distribution (sid) this problem has been fixed in
version 0.9.8b-3

We recommend that you upgrade your openssl packages.  Note that services
linking against the openssl shared libraries will need to be restarted.
Common examples of such services include most Mail Transport Agents, SSH
servers, and web servers.

Debian GNU/Linux 3.1 alias sarge
- --------------------------------

