Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2008-3844 Details

Description

Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externally introduced modification (Trojan Horse) that allows the package authors to have an unknown impact. NOTE: since the malicious packages were not distributed from any official Red Hat sources, the scope of this issue is restricted to users who may have obtained these packages through unofficial distribution points. As of 20080827, no unofficial distributions of this software are known.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://secunia.com/advisories/31575 CVEPermissions RequiredThird Party Advisory
http://secunia.com/advisories/32241 CVEPermissions RequiredThird Party Advisory
http://securitytracker.com/id?1020730 CVEThird Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/44747 CVE
http://support.avaya.com/elmodocs2/security/ASA-2008-399.htm CVEThird Party Advisory

see all 18 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-20Improper Input Validation[email protected]

Affected Products

ProductVersions
redhat enterprise linux
4.5.z
5.0

CPE

  • cpe:2.3:o:redhat:enterprise_linux:4.5.z:*:as:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux:4.5.z:*:es:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
redhat enterprise linux desktop
4
5

CPE

  • cpe:2.3:o:redhat:enterprise_linux_desktop:4:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_desktop:5:*:client:*:*:*:*:*

Remediation

  • No remediation found in references.
openbsd openssh
All versions

CPE

  • cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

9 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2008-3844
NVD Published Date:
Aug 27, 2008
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2008-3844 Details - Not Deferred