CVE-2008-0166
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 70.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 70.72% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-338
- Affected
- openssl/openssl · canonical/ubuntu linux · debian/debian linux
- Source
- cve@mitre.org
References
- http://metasploit.com/users/hdm/tools/debian-openssl/Broken Link
- http://secunia.com/advisories/30136Broken Link, Vendor Advisory
- http://secunia.com/advisories/30220Broken Link, Vendor Advisory
- http://secunia.com/advisories/30221Broken Link, Vendor Advisory
- http://secunia.com/advisories/30231Broken Link, Vendor Advisory
- http://secunia.com/advisories/30239Broken Link, Vendor Advisory
- http://secunia.com/advisories/30249Broken Link, Vendor Advisory
- http://sourceforge.net/mailarchive/forum.php?thread_name=48367252.7070603%40shemesh.biz&forum_name=rsyncrypto-develThird Party Advisory
- http://www.debian.org/security/2008/dsa-1571Mailing List, Patch, Vendor Advisory
- http://www.debian.org/security/2008/dsa-1576Mailing List, Patch
- http://www.kb.cert.org/vuls/id/925211Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/492112/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/29179Broken Link, Exploit, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020017Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-612-1Patch, Third Party Advisory
- http://www.ubuntu.com/usn/usn-612-2Patch, Third Party Advisory
- http://www.ubuntu.com/usn/usn-612-3Third Party Advisory
- http://www.ubuntu.com/usn/usn-612-4Third Party Advisory
- http://www.ubuntu.com/usn/usn-612-7Third Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA08-137A.htmlBroken Link, Third Party Advisory, US Government Resource
- https://16years.secvuln.info
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42375Third Party Advisory, VDB Entry
- https://news.ycombinator.com/item?id=40333169
- https://www.exploit-db.com/exploits/5622Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/5632Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/5720Exploit, Third Party Advisory, VDB Entry
- http://metasploit.com/users/hdm/tools/debian-openssl/Broken Link
- http://secunia.com/advisories/30136Broken Link, Vendor Advisory
- http://secunia.com/advisories/30220Broken Link, Vendor Advisory
- http://secunia.com/advisories/30221Broken Link, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.