National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

CVE-2008-3844 Detail

Current Description

Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externally introduced modification (Trojan Horse) that allows the package authors to have an unknown impact. NOTE: since the malicious packages were not distributed from any official Red Hat sources, the scope of this issue is restricted to users who may have obtained these packages through unofficial distribution points. As of 20080827, no unofficial distributions of this software are known.

Source:  MITRE
View Analysis Description

Evaluator Description

This alert is primarily for those who may obtain Red Hat binary packages via channels other than those of official Red Hat subscribers. Packages obtained by Red Hat Enterprise Linux subscribers via Red Hat Network are not at risk. Redhat has provided a shell script which lists the affected packages and can verify that none of them are installed on a system at the following location: https://www.redhat.com/security/data/openssh-blacklist-1.0.sh

Severity



CVSS 3.x Severity and Metrics:

NIST CVSS score
NIST: NVD
Base Score: N/A
NVD score not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource
http://securitytracker.com/id?1020730 Third Party Advisory VDB Entry
http://support.avaya.com/elmodocs2/security/ASA-2008-399.htm Third Party Advisory
http://www.redhat.com/security/data/openssh-blacklist.html Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0855.html Not Applicable
http://www.securityfocus.com/bid/30794 Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2008/2821 Broken Link
https://exchange.xforce.ibmcloud.com/vulnerabilities/44747

Weakness Enumeration

CWE-ID CWE Name Source
CWE-20 Improper Input Validation NIST  

Known Affected Software Configurations Switch to CPE 2.2

Configuration 1 ( hide )
 cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
     Show Matching CPE(s)
Running on/with
 cpe:2.3:o:redhat:enterprise_linux:4.5.z:*:as:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:o:redhat:enterprise_linux:4.5.z:*:es:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:o:redhat:enterprise_linux_desktop:4:*:*:*:*:*:*:*
     Show Matching CPE(s)
 cpe:2.3:o:redhat:enterprise_linux_desktop:5:*:client:*:*:*:*:*
     Show Matching CPE(s)


Change History

5 change records found - show changes

Quick Info

CVE Dictionary Entry:
CVE-2008-3844
NVD Published Date:
08/27/2008
NVD Last Modified:
08/07/2017