An ill-advised patch in the libssl toolkit was discovered by upstream ssl developers. The patch removed all sources of randomness from the key generation process, except for one the user ID of the key-generating process which is, as youd expect, not so very random, leading to the generation of eminently guessable keys. The implications are myriad for one, all those supposedly secure web shops which ran on Debian servers werent in fact secure. Even worse, ssh, which depends on libs, was also vulnerable.”]
Source: https://www.bitdefender.com/blog/hotforsecurity/debian/