Yikes!
It looks like a hacker was somehow able to penetrate Red Hat, get access to the keys that they use to sign their code, and include bogus OpenSSH packages in some versions of their software. Fortunately, this problem was caught fairly quickly, and you can now download clean versions of the affected software as well as a tool to check to make sure that you haven't been compromised.
I'd assume that the hackers went after their highest priority targets first, which in this case happened to be OpenSSH. That's an interesting choice, but I'm not sure that I would have done the same thing. If you were a hacker and had a chance to change just one package, which one would it be?





Comments