Luciano Bello discovered that the random number generator in the openssl package is predictable. As a result, cryptographic key material may be guessable. Affected keys include SSH keys, OpenVPN keys, DNSSEC keys, and key material for use in X509 certificates and session keys used in SSL/TLS connections. Keys generated with GnuPG or GNUTLS are not affected. A detector for known weak key material will be published at:
Source: https://lists.debian.org/debian-security-announce/2008/msg00152.html

