The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from the binpkg, and causes multiple systems that use this binpkg to have the same SSL key and certificate.
                
            References
                    Configurations
                    History
                    21 Nov 2024, 00:44
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://osvdb.org/43479 - | |
| References | () http://secunia.com/advisories/29436 - Vendor Advisory | |
| References | () http://security.gentoo.org/glsa/glsa-200803-30.xml - | |
| References | () http://www.securityfocus.com/bid/28350 - | |
| References | () https://bugs.gentoo.org/show_bug.cgi?id=174759 - | |
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/41336 - | 
Information
                Published : 2008-03-18 22:44
Updated : 2025-04-09 00:30
NVD link : CVE-2008-1383
Mitre link : CVE-2008-1383
CVE.ORG link : CVE-2008-1383
JSON object : View
Products Affected
                gentoo
- linux
CWE
                
                    
                        
                        CWE-310
                        
            Cryptographic Issues
