OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating...
Vulnerability Description
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-0166
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.debian.org/security/2008/dsa-1576
- https://www.exploit-db.com/exploits/5622
- http://secunia.com/advisories/30221
- http://sourceforge.net/mailarchive/forum.php?thread_name=48367252.7070603%40shemesh.biz&forum_name=rsyncrypto-devel
- http://www.debian.org/security/2008/dsa-1571
- http://www.securityfocus.com/bid/29179
- http://www.securityfocus.com/archive/1/492112/100/0/threaded
- http://secunia.com/advisories/30239
- http://secunia.com/advisories/30220
- http://www.ubuntu.com/usn/usn-612-7
- http://secunia.com/advisories/30231
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42375
- http://metasploit.com/users/hdm/tools/debian-openssl/
- http://secunia.com/advisories/30249
- http://www.securitytracker.com/id?1020017
- https://www.exploit-db.com/exploits/5632
- http://www.ubuntu.com/usn/usn-612-4
- http://www.ubuntu.com/usn/usn-612-2
- http://www.us-cert.gov/cas/techalerts/TA08-137A.html
- http://www.kb.cert.org/vuls/id/925211
- https://www.exploit-db.com/exploits/5720
- http://secunia.com/advisories/30136
- http://www.ubuntu.com/usn/usn-612-3
- http://www.ubuntu.com/usn/usn-612-1
- https://16years.secvuln.info
- https://news.ycombinator.com/item?id=40333169
More from openssl
View All →Affected Vendor
openssl
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.