CVE-2008-0166

NameCVE-2008-0166
DescriptionOpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-1571-1, DSA-1576-1
NVD severityhigh (attack range: remote)
Debian/oldoldstablenot vulnerable.
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openssh (PTS)squeeze, squeeze (security)1:5.5p1-6+squeeze5fixed
squeeze (lts)1:5.5p1-6+squeeze6fixed
wheezy1:6.0p1-4+deb7u2fixed
wheezy (security)1:6.0p1-4+deb7u1fixed
jessie1:6.7p1-5fixed
stretch, sid1:6.9p1-1fixed
openssl (PTS)squeeze, squeeze (security)0.9.8o-4squeeze14fixed
squeeze (lts)0.9.8o-4squeeze21fixed
wheezy1.0.1e-2+deb7u13fixed
wheezy (security)1.0.1e-2+deb7u17fixed
jessie1.0.1k-3fixed
jessie (security)1.0.1k-3+deb8u1fixed
stretch, sid1.0.2d-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
opensshsource(unstable)4.7p1-9high
opensshsourceetch1:4.3p2-9etch2highDSA-1576-1
opensslsource(unstable)0.9.8g-9high
opensslsourceetch0.9.8c-4etch3highDSA-1571-1
opensslsourcesarge(not affected)

Notes

[sarge] - openssl <not-affected> (Vulnerable code not present)
http://www.debian.org/security/key-rollover/

Search for package or bug name: Reporting problems