PT-2008-1067 · Red Hat+1 · Red Hat+6

Published

2008-08-22

·

Updated

2026-03-06

·

CVE-2008-3844

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openssh-askpass-gnome version 3.9p1 openssh-askpass version 3.9p1 openssh version 3.9p1 openssh-server version 3.9p1 openssh-clients version 3.9p1
Description The issue involves multiple vulnerabilities in OpenSSH packages for Red Hat Enterprise Linux and CentOS operating systems. These vulnerabilities can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. The scope of this issue is restricted to users who may have obtained malicious packages through unofficial distribution points.
Recommendations For openssh-askpass-gnome version 3.9p1, consider disabling the package until a patch is available. For openssh-askpass version 3.9p1, restrict access to the package to minimize the risk of exploitation. For openssh version 3.9p1, avoid using the package until the issue is resolved. For openssh-server version 3.9p1, consider disabling the server until a patch is available. For openssh-clients version 3.9p1, restrict access to the clients to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2015-06466
BDU:2015-06468
BDU:2015-06470
BDU:2015-06472
BDU:2015-06474
BDU:2015-08365
BDU:2015-08366
BDU:2015-08367
BDU:2015-08368
BDU:2015-08369
CVE-2008-3844
RHSA-2008:0855
RHSA-2008_0855

Affected Products

Centos
Red Hat
Openssh
Openssh-Askpass
Openssh-Askpass-Gnome
Openssh-Clients
Openssh-Server