Exhibit A: CVE-2013-2228.
As described inthe relevant entry [0] on Debian's Security Tracker:
> SaltStack RSA Key Generation allows remote users to decrypt communications
The fix [1]:
- gen = RSA.gen_key(keysize, 1, callback=lambda x, y, z: None)
+ gen = RSA.gen_key(keysize, 65537, callback=lambda x, y, z: None)
---[0]: https://security-tracker.debian.org/tracker/CVE-2013-2228
[1]: https://github.com/saltstack/salt/commit/e8ce66cf688b43aeb3e...