CVE-2008-0166
Summary
| CVE | CVE-2008-0166 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-05-13 17:20:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Problem Types: CWE-338 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 2.0 | [email protected] | Primary | 7.8 | AV:N/AC:L/Au:N/C:C/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:C/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 6.06 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 7.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 7.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 8.04 | All | All | All |
| Operating System | Debian | Debian Linux | 4.0 | All | All | All |
| Application | Openssl | Openssl | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| USN-612-1: OpenSSL vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Patch, Third Party Advisory |
| Debian OpenSSL Predictable Random Number Generator and Update - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| Debian OpenSSL Predictable PRNG Toys | af854a3a-2127-422b-91ae-364da2661108 | metasploit.com | Broken Link |
| news.ycombinator.com/item | af854a3a-2127-422b-91ae-364da2661108 | news.ycombinator.com | |
| SourceForge.net: rsync friendly file encryption: rsyncrypto-devel | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Third Party Advisory |
| Ubuntu update for openssh - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| US-CERT Technical Cyber Security Alert TA08-137A -- Debian/Ubuntu OpenSSL Random Number Generator Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | Broken Link, Third Party Advisory, US Government Resource |
| Debian -- Security Information -- DSA-1571-1 openssl | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Mailing List, Patch, Vendor Advisory |
| USN-612-2: OpenSSH vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Patch, Third Party Advisory |
| Ubuntu update for ssl-cert - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| Ubuntu update for openvpn - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| Ubuntu update for openssl - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| Debian OpenSSL Package Random Number Generator Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Exploit, Third Party Advisory, VDB Entry |
| Debian OpenSSL Predictable PRNG Bruteforce SSH Exploit (Python) | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| Debian OpenSSL Predictable PRNG Bruteforce SSH Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| USN-612-4: ssl-cert vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| Debian OpenSSL Predictable PRNG Bruteforce SSH Exploit (ruby) | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| US-CERT Vulnerability Note VU#925211 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | Third Party Advisory, US Government Resource |
| SecurityTracker.com Archives - OpenSSL for Debian/Ubuntu Predictable RNG Lets Remote Users Determine Cryptographic Keys | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| Debian -- Security Information -- DSA-1576-1 openssh | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Mailing List, Patch |
| USN-612-7: OpenSSH update | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| Debian update for openssh - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link, Vendor Advisory |
| USN-612-3: OpenVPN vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Third Party Advisory |
| 16years.secvuln.info | af854a3a-2127-422b-91ae-364da2661108 | 16years.secvuln.info | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-05-13 | Mark J Cox | Not vulnerable. This flaw was caused by a third-party vendor patch to the OpenSSL library. This patch has never been used by Red Hat, and this issue therefore does not affect any Fedora, Red Hat, or upstream supplied OpenSSL packages. |
There are currently no legacy QID mappings associated with this CVE.