- http://www.theregist...an_openssl_bug/
13 May 2008 - "Debian has warned of a vulnerability in its cryptographic functions that could leave systems open to attack. The use of a cryptographically flawed pseudo random number generator in Debian's implementation of OpenSSL meant that potentially predictable keys were generated. Versions of Debian's OpenSSL packages starting with 0.9.8c-1 (released in September 2006) are potentially vulnerable...
- http://secunia.com/advisories/30220/
Release Date: 2008-05-13
Critical: Highly critical
Impact: Security Bypass, DoS, System access
Where: From remote
Solution Status: Vendor Patch
...The security issue is reported in Debian's OpenSSL packages starting with 0.9.8c-1... affects all keys generated with an affected package...
Original Advisory:
http://lists.debian....8/msg00152.html

Edited by AplusWebMaster, 16 May 2008 - 10:05 AM.