{"api_version":"1","generated_at":"2026-07-23T21:09:53+00:00","cve":"CVE-2008-0166","urls":{"html":"https://cve.report/CVE-2008-0166","api":"https://cve.report/api/cve/CVE-2008-0166.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-0166","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-0166"},"summary":{"title":"CVE-2008-0166","description":"OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-05-13 17:20:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-338","n/a"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.ubuntu.com/usn/usn-612-1","name":"http://www.ubuntu.com/usn/usn-612-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"USN-612-1: OpenSSL vulnerability | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/30220","name":"http://secunia.com/advisories/30220","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Debian OpenSSL Predictable Random Number Generator and Update - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://metasploit.com/users/hdm/tools/debian-openssl/","name":"http://metasploit.com/users/hdm/tools/debian-openssl/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Debian OpenSSL Predictable PRNG Toys","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://news.ycombinator.com/item?id=40333169","name":"https://news.ycombinator.com/item?id=40333169","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://sourceforge.net/mailarchive/forum.php?thread_name=48367252.7070603%40shemesh.biz&forum_name=rsyncrypto-devel","name":"http://sourceforge.net/mailarchive/forum.php?thread_name=48367252.7070603%40shemesh.biz&forum_name=rsyncrypto-devel","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"SourceForge.net: rsync friendly file encryption: rsyncrypto-devel","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/30239","name":"http://secunia.com/advisories/30239","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Ubuntu update for openssh - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA08-137A.html","name":"http://www.us-cert.gov/cas/techalerts/TA08-137A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA08-137A -- Debian/Ubuntu OpenSSL Random Number Generator Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2008/dsa-1571","name":"http://www.debian.org/security/2008/dsa-1571","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Patch","Vendor Advisory"],"title":"Debian -- Security Information -- DSA-1571-1 openssl","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-612-2","name":"http://www.ubuntu.com/usn/usn-612-2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"USN-612-2: OpenSSH vulnerability | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/30231","name":"http://secunia.com/advisories/30231","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Ubuntu update for ssl-cert - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/30136","name":"http://secunia.com/advisories/30136","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Ubuntu update for openvpn - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/30221","name":"http://secunia.com/advisories/30221","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Ubuntu update for openssl - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42375","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42375","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/29179","name":"http://www.securityfocus.com/bid/29179","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Exploit","Third Party Advisory","VDB Entry"],"title":"Debian OpenSSL Package Random Number Generator Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.exploit-db.com/exploits/5720","name":"https://www.exploit-db.com/exploits/5720","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Debian OpenSSL Predictable PRNG Bruteforce SSH Exploit (Python)","mime":"text/x-python","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/492112/100/0/threaded","name":"http://www.securityfocus.com/archive/1/492112/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/5622","name":"https://www.exploit-db.com/exploits/5622","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Debian OpenSSL Predictable PRNG Bruteforce SSH Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-612-4","name":"http://www.ubuntu.com/usn/usn-612-4","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-612-4: ssl-cert vulnerability | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/5632","name":"https://www.exploit-db.com/exploits/5632","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Debian OpenSSL Predictable PRNG Bruteforce SSH Exploit (ruby)","mime":"text/x-ruby","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/925211","name":"http://www.kb.cert.org/vuls/id/925211","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Vulnerability Note VU#925211","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1020017","name":"http://www.securitytracker.com/id?1020017","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - OpenSSL for Debian/Ubuntu Predictable RNG Lets Remote Users Determine Cryptographic Keys","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2008/dsa-1576","name":"http://www.debian.org/security/2008/dsa-1576","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Patch"],"title":"Debian -- Security Information -- DSA-1576-1 openssh","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-612-7","name":"http://www.ubuntu.com/usn/usn-612-7","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-612-7: OpenSSH update | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/30249","name":"http://secunia.com/advisories/30249","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Debian update for openssh - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-612-3","name":"http://www.ubuntu.com/usn/usn-612-3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-612-3: OpenVPN vulnerability | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://16years.secvuln.info","name":"https://16years.secvuln.info","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-0166","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-0166","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"166","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"6.06","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"166","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"7.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"166","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"7.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"166","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"8.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"-","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"166","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"166","vulnerable":"1","versionEndIncluding":"0.9.8g","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openssl","cpe5":"openssl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2008-0166","organization":"Red Hat","lastmodified":"2008-05-13","contributor":"Mark J Cox","statementText":"Not vulnerable. This flaw was caused by a third-party vendor patch to the OpenSSL library. This patch has never been used by Red Hat, and this issue therefore does not affect any Fedora, Red Hat, or upstream supplied OpenSSL packages.","cve_year":"2008","cve_id":"166","crc32":"b62fa8b8"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T07:39:32.856Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"DSA-1576","tags":["vendor-advisory","x_transferred"],"url":"http://www.debian.org/security/2008/dsa-1576"},{"name":"5622","tags":["exploit","x_transferred"],"url":"https://www.exploit-db.com/exploits/5622"},{"name":"30221","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/30221"},{"name":"[rsyncrypto-devel] 20080523 Advisory - Rsyncrypto maybe affected from Debian OpenSSL reduced entropy problem","tags":["mailing-list","x_transferred"],"url":"http://sourceforge.net/mailarchive/forum.php?thread_name=48367252.7070603%40shemesh.biz&forum_name=rsyncrypto-devel"},{"name":"DSA-1571","tags":["vendor-advisory","x_transferred"],"url":"http://www.debian.org/security/2008/dsa-1571"},{"name":"29179","tags":["vdb-entry","x_transferred"],"url":"http://www.securityfocus.com/bid/29179"},{"name":"20080515 Debian generated SSH-Keys working exploit","tags":["mailing-list","x_transferred"],"url":"http://www.securityfocus.com/archive/1/492112/100/0/threaded"},{"name":"30239","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/30239"},{"name":"30220","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/30220"},{"name":"USN-612-7","tags":["vendor-advisory","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-612-7"},{"name":"30231","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/30231"},{"name":"openssl-rng-weak-security(42375)","tags":["vdb-entry","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42375"},{"tags":["x_transferred"],"url":"http://metasploit.com/users/hdm/tools/debian-openssl/"},{"name":"30249","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/30249"},{"name":"1020017","tags":["vdb-entry","x_transferred"],"url":"http://www.securitytracker.com/id?1020017"},{"name":"5632","tags":["exploit","x_transferred"],"url":"https://www.exploit-db.com/exploits/5632"},{"name":"USN-612-4","tags":["vendor-advisory","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-612-4"},{"name":"USN-612-2","tags":["vendor-advisory","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-612-2"},{"name":"TA08-137A","tags":["third-party-advisory","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA08-137A.html"},{"name":"VU#925211","tags":["third-party-advisory","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/925211"},{"name":"5720","tags":["exploit","x_transferred"],"url":"https://www.exploit-db.com/exploits/5720"},{"name":"30136","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/30136"},{"name":"USN-612-3","tags":["vendor-advisory","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-612-3"},{"name":"USN-612-1","tags":["vendor-advisory","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-612-1"},{"tags":["x_transferred"],"url":"https://16years.secvuln.info"},{"tags":["x_transferred"],"url":"https://news.ycombinator.com/item?id=40333169"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2024-05-12T20:03:03.670Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"DSA-1576","tags":["vendor-advisory"],"url":"http://www.debian.org/security/2008/dsa-1576"},{"name":"5622","tags":["exploit"],"url":"https://www.exploit-db.com/exploits/5622"},{"name":"30221","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/30221"},{"name":"[rsyncrypto-devel] 20080523 Advisory - Rsyncrypto maybe affected from Debian OpenSSL reduced entropy problem","tags":["mailing-list"],"url":"http://sourceforge.net/mailarchive/forum.php?thread_name=48367252.7070603%40shemesh.biz&forum_name=rsyncrypto-devel"},{"name":"DSA-1571","tags":["vendor-advisory"],"url":"http://www.debian.org/security/2008/dsa-1571"},{"name":"29179","tags":["vdb-entry"],"url":"http://www.securityfocus.com/bid/29179"},{"name":"20080515 Debian generated SSH-Keys working exploit","tags":["mailing-list"],"url":"http://www.securityfocus.com/archive/1/492112/100/0/threaded"},{"name":"30239","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/30239"},{"name":"30220","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/30220"},{"name":"USN-612-7","tags":["vendor-advisory"],"url":"http://www.ubuntu.com/usn/usn-612-7"},{"name":"30231","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/30231"},{"name":"openssl-rng-weak-security(42375)","tags":["vdb-entry"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42375"},{"url":"http://metasploit.com/users/hdm/tools/debian-openssl/"},{"name":"30249","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/30249"},{"name":"1020017","tags":["vdb-entry"],"url":"http://www.securitytracker.com/id?1020017"},{"name":"5632","tags":["exploit"],"url":"https://www.exploit-db.com/exploits/5632"},{"name":"USN-612-4","tags":["vendor-advisory"],"url":"http://www.ubuntu.com/usn/usn-612-4"},{"name":"USN-612-2","tags":["vendor-advisory"],"url":"http://www.ubuntu.com/usn/usn-612-2"},{"name":"TA08-137A","tags":["third-party-advisory"],"url":"http://www.us-cert.gov/cas/techalerts/TA08-137A.html"},{"name":"VU#925211","tags":["third-party-advisory"],"url":"http://www.kb.cert.org/vuls/id/925211"},{"name":"5720","tags":["exploit"],"url":"https://www.exploit-db.com/exploits/5720"},{"name":"30136","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/30136"},{"name":"USN-612-3","tags":["vendor-advisory"],"url":"http://www.ubuntu.com/usn/usn-612-3"},{"name":"USN-612-1","tags":["vendor-advisory"],"url":"http://www.ubuntu.com/usn/usn-612-1"},{"url":"https://16years.secvuln.info"},{"url":"https://news.ycombinator.com/item?id=40333169"}]}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-0166","datePublished":"2008-05-13T17:00:00.000Z","dateReserved":"2008-01-09T00:00:00.000Z","dateUpdated":"2024-08-07T07:39:32.856Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-05-13 17:20:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-338","n/a"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*","versionStartIncluding":"0.9.8c-1","versionEndIncluding":"0.9.8g","matchCriteriaId":"8EEFA1C8-85D4-425F-A987-29AC6D10C303"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*","matchCriteriaId":"454A5D17-B171-4F1F-9E0B-F18D1E5CA9FD"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*","matchCriteriaId":"6EBDAFF8-DE44-4E80-B6BD-E341F767F501"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*","matchCriteriaId":"823BF8BE-2309-4F67-A5E2-EAD98F723468"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*","matchCriteriaId":"7EBFE35C-E243-43D1-883D-4398D71763CC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*","matchCriteriaId":"0F92AB32-E7DE-43F4-B877-1F41FA162EC7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"166","Ordinal":"1","Title":"CVE-2008-0166","CVE":"CVE-2008-0166","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"166","Ordinal":"1","NoteData":"OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.","Type":"Description","Title":"CVE-2008-0166"},{"CveYear":"2008","CveId":"166","Ordinal":"2","NoteData":"2008-05-13","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"166","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}