PT-2008-1041 · Openssl · Openssl

·

CVE-2008-0166

·

Published

2008-05-13

·

Updated

2026-01-27

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions 0.9.8c-1 through 0.9.8g-9
Description The issue concerns a random number generator in OpenSSL that generates predictable numbers, making it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys. This affects Debian-based operating systems. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For OpenSSL versions 0.9.8c-1 through 0.9.8g-9, update to a version newer than 0.9.8g-9 to resolve the issue. At the moment, there is no information about additional mitigation measures.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04116
CVE-2008-0166
DSA-1571-1
DSA-1576-1
OPENSSLUNAUTHORIZEDACCESS

Affected Products

Openssl