Package: synergy
Version: 1.8.8-stable+dfsg.1-1.1
Severity: grave
Tags: security


Quack,

With recent openssl upgrade (1.1.0h-4 -> 1.1.1~~pre9-1) the client fails to connect with error routines:SSL_CTX_use_certificate:ee key too small.

The following script is used to generate the key: /usr/share/synergy/gen_ssl_pem.sh This script creates a 1024 bits RSA key, which is too small to be secure.
This means it is security issue in all Debian suites.

Regards.

--
Marc Dequènes

Reply via email to