Lucene search

K
prionPRIOn knowledge basePRION:CVE-2008-3280
HistoryMay 21, 2021 - 8:15 p.m.

Design/Logic Flaw

2021-05-2120:15:00
PRIOn knowledge base
www.prio-n.com
8

6.5 Medium

AI Score

Confidence

High

0.133 Low

EPSS

Percentile

95.6%

It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Random Number Generator (CVE-2008-0166). In combination with the DNS Cache Poisoning issue (CVE-2008-1447) and the fact that almost all SSL/TLS implementations do not consult CRLs (currently an untracked issue), this means that it is impossible to rely on these OPs.