The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from the binpkg, and causes multiple systems that use this binpkg to have the same SSL key and certificate.
References
Configurations
History
21 Nov 2024, 00:44
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/43479 - | |
References | () http://secunia.com/advisories/29436 - Vendor Advisory | |
References | () http://security.gentoo.org/glsa/glsa-200803-30.xml - | |
References | () http://www.securityfocus.com/bid/28350 - | |
References | () https://bugs.gentoo.org/show_bug.cgi?id=174759 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/41336 - |
Information
Published : 2008-03-18 22:44
Updated : 2024-11-21 00:44
NVD link : CVE-2008-1383
Mitre link : CVE-2008-1383
CVE.ORG link : CVE-2008-1383
JSON object : View
Products Affected
gentoo
- linux
CWE
CWE-310
Cryptographic Issues