CWE
20
Advisory Published
Updated

CVE-2008-3844: Input Validation

First published: Wed Aug 27 2008(Updated: )

Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externally introduced modification (Trojan Horse) that allows the package authors to have an unknown impact. NOTE: since the malicious packages were not distributed from any official Red Hat sources, the scope of this issue is restricted to users who may have obtained these packages through unofficial distribution points. As of 20080827, no unofficial distributions of this software are known.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Red Hat Enterprise Linux=4.5.z
Red Hat Enterprise Linux=4.5.z
Red Hat Enterprise Linux=5.0
redhat enterprise Linux desktop=4
redhat enterprise Linux desktop=5
OpenSSH

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2008-3844?

    CVE-2008-3844 is classified with unknown impact severity due to the presence of a Trojan Horse in affected packages.

  • How do I fix CVE-2008-3844?

    To mitigate CVE-2008-3844, users should remove the compromised OpenSSH packages and reinstall from trusted sources.

  • Which software is affected by CVE-2008-3844?

    CVE-2008-3844 affects certain packages of OpenSSH for Red Hat Enterprise Linux versions 4 and 5, specifically those signed in August 2008.

  • How can I check if my system is vulnerable to CVE-2008-3844?

    You can verify the installed version of OpenSSH on your system against the affected packages list for CVE-2008-3844.

  • Is there a way to prevent vulnerabilities like CVE-2008-3844?

    To prevent vulnerabilities like CVE-2008-3844, always obtain software packages from verified and secure sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203