MD5 is comprehensively broken at this point

Bug #1883983 reported by Robert Collins
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
debhelper (Debian)
Fix Released
Unknown
debsums (Debian)
Confirmed
Unknown
debsums (Ubuntu)
New
Undecided
Unassigned
dpkg (Ubuntu)
New
Undecided
Unassigned

Bug Description

https://en.wikipedia.org/wiki/MD5#Collision_vulnerabilities - MD5 is comprehensively broken at this point. Debsums still claims to be using md5.

Perhaps it is time to either remove debsums as being insufficient to the task, or upgrade the hash that debsums uses to a stronger hash.

Revision history for this message
Axel Beckert (xtaran) wrote :

debsums uses MD5 because dpkg uses MD5.

Changed in debhelper (Debian):
status: Unknown → New
Changed in debsums (Debian):
status: Unknown → Confirmed
Changed in debhelper (Debian):
status: New → Won't Fix
Changed in debhelper (Debian):
status: Won't Fix → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.