Debian OpenSSL weak keys (CVE-2008-0166)
A Debian packager removed a line from OpenSSL's random-number seeding code in 2006. The change made the PRNG output predictable, so every SSH and SSL key generated on affected Debian systems had only a small number of possible values. Researchers found the flaw in 2008.
Millions of keys across Debian and Ubuntu systems had to be regenerated within days.
It became a textbook case of how a small change outside upstream source can create a security catastrophe.
Like the curl miscompiles, the vulnerability lived not in the application's logic but in the layer that turns source into a usable system — here the build and packaging process, there the compiler.
