CVE-2008-3844: Input Validation
Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externally introduced modification (Trojan Horse) that allows the package authors to have an unknown impact. NOTE: since the malicious packages were not distributed from any official Red Hat sources, the scope of this issue is restricted to users who may have obtained these packages through unofficial distribution points. As of 20080827, no unofficial distributions of this software are known.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3844?
CVE-2008-3844 is classified with unknown impact severity due to the presence of a Trojan Horse in affected packages.
How do I fix CVE-2008-3844?
To mitigate CVE-2008-3844, users should remove the compromised OpenSSH packages and reinstall from trusted sources.
Which software is affected by CVE-2008-3844?
CVE-2008-3844 affects certain packages of OpenSSH for Red Hat Enterprise Linux versions 4 and 5, specifically those signed in August 2008.
How can I check if my system is vulnerable to CVE-2008-3844?
You can verify the installed version of OpenSSH on your system against the affected packages list for CVE-2008-3844.
Is there a way to prevent vulnerabilities like CVE-2008-3844?
To prevent vulnerabilities like CVE-2008-3844, always obtain software packages from verified and secure sources.