CVE-2008-5659

NameCVE-2008-5659
DescriptionThe gnu.java.security.util.PRNG class in GNU Classpath 0.97.2 and earlier uses a predictable seed based on the system time, which makes it easier for context-dependent attackers to conduct brute force attacks against cryptographic routines that use this class for randomness, as demonstrated against DSA private keys.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs512532, 559789

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
classpathsource(unstable)2:0.98-1low512532
libgnucrypto-javasource(unstable)(unfixed)low559789

Notes

[lenny] - classpath <no-dsa> (Minor issue)
[lenny] - libgnucrypto-java <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems