First published: Tue Mar 18 2008(Updated: )
The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from the binpkg, and causes multiple systems that use this binpkg to have the same SSL key and certificate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gentoo Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1383 is considered a medium severity vulnerability due to its potential for exposing sensitive SSL certificates and keys.
To mitigate CVE-2008-1383, ensure SSL keys are not stored in binpkgs and elevate access controls on SSL configurations.
CVE-2008-1383 affects systems running Gentoo Linux that utilize the docert function in ssl-cert.eclass.
If exploited, CVE-2008-1383 allows local users to extract SSL keys from binpkgs, leading to possible man-in-the-middle attacks.
After detecting CVE-2008-1383, replace the compromised SSL keys and review the systems for unauthorized access.