Security Advisory

CVE-2008-1383

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-03-18 22:00:00
Last updated 2024-08-07 08:17:34
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from the binpkg, and causes multiple systems that use this binpkg to have the same SSL key and certificate.