<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/16-years-of-cve-2008-0166---debian-openssl-bug-rdhbficok" -->

---
title: 16 years of CVE-2008-0166 - Debian OpenSSL Bug | daily.dev
description: In 2008, Debian Linux announced a severe security vulnerability in its OpenSSL package, limiting the possible keys. In 2024, many DKIM setups still use...
canonical: https://daily.dev/posts/16-years-of-cve-2008-0166---debian-openssl-bug-rdhbficok
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: 16 years of CVE-2008-0166 - Debian OpenSSL Bug | daily.dev
og:description: In 2008, Debian Linux announced a severe security vulnerability in its OpenSSL package, limiting the possible keys. In 2024, many DKIM setups still use...
og:url: https://daily.dev/posts/16-years-of-cve-2008-0166---debian-openssl-bug-rdhbficok
og:image: https://api.daily.dev/og/posts/RDHBFIcoK.png
og:image:alt: 16 years of CVE-2008-0166 - Debian OpenSSL Bug
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# 16 years of CVE-2008-0166 - Debian OpenSSL Bug

**[Lobsters](https://daily.dev/sources/lobsters)** · 7 min read · 0 upvotes · 0 comments

## Summary

In 2008, Debian Linux announced a severe security vulnerability in its OpenSSL package, limiting the possible keys. In 2024, many DKIM setups still use vulnerable keys. DKIM allows signing emails with a cryptographic key, but a large number of hosts were found to be vulnerable to the Debian OpenSSL bug. Companies configured DKIM keys in 2007 and never changed them, leading to potential email forging. The DKIM ecosystem lacks proper cryptographic security and uses substandard RSA key sizes. A tool called badkeys can be used to scan DKIM keys and identify vulnerabilities.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://16years.secvuln.info/>

---

Tags: [#security](https://daily.dev/tags/security), [#vulnerability](https://daily.dev/tags/vulnerability), [#cryptography](https://daily.dev/tags/cryptography)

[View this post on daily.dev](https://daily.dev/posts/16-years-of-cve-2008-0166---debian-openssl-bug-rdhbficok)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"16 years of CVE-2008-0166 - Debian OpenSSL Bug","url":"https://daily.dev/posts/16-years-of-cve-2008-0166---debian-openssl-bug-rdhbficok","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/16-years-of-cve-2008-0166---debian-openssl-bug-rdhbficok"},"datePublished":"2024-05-12T11:19:50.541Z","dateModified":"2024-05-12T11:19:48.805Z","description":"In 2008, Debian Linux announced a severe security vulnerability in its OpenSSL package, limiting the possible keys. In 2024, many DKIM setups still use...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/95a4343c851ee729f02efd6ba90f2312?_a=AQAEuiZ","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/95a4343c851ee729f02efd6ba90f2312?_a=AQAEuiZ","isAccessibleForFree":true,"articleSection":"Lobsters","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Lobsters","logo":"https://media.daily.dev/image/upload/s--tl8v_Fku--/f_auto,t_logo/v1698841318/logos/lobste.jpg","url":"https://daily.dev/sources/lobsters"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/16-years-of-cve-2008-0166---debian-openssl-bug-rdhbficok","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,vulnerability,cryptography","timeRequired":"PT7M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Lobsters","item":"https://daily.dev/sources/lobsters"},{"@type":"ListItem","position":3,"name":"16 years of CVE-2008-0166 - Debian OpenSSL Bug"}]}
```

