CVE-2008-3844

N/A Unknown
Published: August 27, 2008 Modified: April 23, 2026
View on NVD

Description

Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externally introduced modification (Trojan Horse) that allows the package authors to have an unknown impact. NOTE: since the malicious packages were not distributed from any official Red Hat sources, the scope of this issue is restricted to users who may have obtained these packages through unofficial distribution points. As of 20080827, no unofficial distributions of this software are known.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/31575
Source: cve@mitre.org
Permissions Required Third Party Advisory
http://secunia.com/advisories/32241
Source: cve@mitre.org
Permissions Required Third Party Advisory
http://securitytracker.com/id?1020730
Source: cve@mitre.org
Third Party Advisory VDB Entry
http://support.avaya.com/elmodocs2/security/ASA-2008-399.htm
Source: cve@mitre.org
Third Party Advisory
http://www.redhat.com/security/data/openssh-blacklist.html
Source: cve@mitre.org
Third Party Advisory
http://www.securityfocus.com/bid/30794
Source: cve@mitre.org
Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2008/2821
Source: cve@mitre.org
Broken Link
http://secunia.com/advisories/31575
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required Third Party Advisory
http://secunia.com/advisories/32241
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required Third Party Advisory
http://securitytracker.com/id?1020730
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
http://support.avaya.com/elmodocs2/security/ASA-2008-399.htm
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.redhat.com/security/data/openssh-blacklist.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.redhat.com/support/errata/RHSA-2008-0855.html
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
http://www.securityfocus.com/bid/30794
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
http://www.vupen.com/english/advisories/2008/2821
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
https://exchange.xforce.ibmcloud.com/vulnerabilities/44747
Source: af854a3a-2127-422b-91ae-364da2661108

18 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

redhat openbsd