us-cert.gov — For almost two years the OpenSSL library used by Linux distribution Debian and Ubuntu has been generating useless cryptographic keys — although Debian has issued a patch, experts warn that systems may still be exposed. "Patching the vulnerability does not remove the vulnerability — it just prevents it from happening from that point on."