ssl-cert: certificate disclosure
| Package(s): | ssl-cert |
CVE #(s): | CVE-2008-1383
|
| Created: | March 20, 2008 |
Updated: | March 26, 2008 |
| Description: |
From the Gentoo alert:
Robin Johnson reported that the docert() function provided by
ssl-cert.eclass can be called by source building stages of an ebuild,
such as src_compile() or src_install(), which will result in the
generated SSL keys being included inside binary packages (binpkgs).
A local attacker could recover the SSL keys from publicly readable
binary packages when "emerge" is called with the "--buildpkg (-b)" or
"--buildpkgonly (-B)" option. Remote attackers can recover these keys
if the packages are served to a network. |
| Alerts: |
|