CVE-2008-0166

NameCVE-2008-0166
DescriptionOpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based ...
SourceCVE (at NVD; oss-sec, OSVDB, EDB, Red Hat, Ubuntu, Gentoo, SuSE, more)
ReferencesDSA-1571-1, DSA-1576-1
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openssh (PTS)squeeze1:5.5p1-6+squeeze4fixed
squeeze (security)1:5.5p1-6+squeeze5fixed
wheezy1:6.0p1-4fixed
wheezy (security)1:6.0p1-4+deb7u1fixed
jessie1:6.6p1-3fixed
sid1:6.6p1-4fixed
openssl (PTS)squeeze, squeeze (security)0.9.8o-4squeeze14fixed
wheezy1.0.1e-2+deb7u4fixed
wheezy (security)1.0.1e-2+deb7u7fixed
jessie1.0.1g-2fixed
sid1.0.1g-3fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
opensshsource(unstable)4.7p1-9high
opensshsourceetch1:4.3p2-9etch2DSA-1576-1
opensslsource(unstable)0.9.8g-9high
opensslsourceetch0.9.8c-4etch3DSA-1571-1
opensslsourcesarge(not affected)

Notes

[sarge] - openssl <not-affected> (Vulnerable code not present)
http://www.debian.org/security/key-rollover/

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Source (SVN)