Two days ago, Debian developpers annouced a huge security breach has been introduced in libssl since september 2006 as a patch to the random number generator (
[DSA 1571-1] New openssl packages fix predictable random number generator ;
Debian -- Security Information -- DSA-1571-1 openssl).
Unfortunately, this unstable version of libssl is the one used for a while in Debian based distributions like Ubuntu, thus all debian or Ubuntu, Kubuntu, Xubuntu (...) users are required to upgrade their version of libssl and also check all key material generated since 2006
For
Gentoo users, nothing has to be done ; their non patched openssl version is ok.
Again, a new reason for not using any debian based distributions...
Gentoo rocks.