[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-3844Date: (C)2008-08-27   (M)2023-12-22


Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externally introduced modification (Trojan Horse) that allows the package authors to have an unknown impact. NOTE: since the malicious packages were not distributed from any official Red Hat sources, the scope of this issue is restricted to users who may have obtained these packages through unofficial distribution points. As of 20080827, no unofficial distributions of this software are known.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 9.3
Exploit Score: 8.6
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1020730
BID-30794
SECUNIA-31575
SECUNIA-32241
ADV-2008-2821
RHSA-2008:0855
http://support.avaya.com/elmodocs2/security/ASA-2008-399.htm
http://www.redhat.com/security/data/openssh-blacklist.html
openssh-rhel-backdoor(44747)

CPE    3
cpe:/o:redhat:enterprise_linux:5.0
cpe:/o:redhat:enterprise_linux_desktop:4
cpe:/a:openbsd:openssh
CWE    1
CWE-20

© SecPod Technologies