Red Hat OpenSSH Backdoor Vulnerability
BID:30794
Info
Red Hat OpenSSH Backdoor Vulnerability
| Bugtraq ID: | 30794 |
| Class: | Design Error |
| CVE: |
CVE-2008-3844 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2008 12:00AM |
| Updated: | May 07 2015 05:24PM |
| Credit: | Reported by Red Hat |
| Vulnerable: |
Redhat openssh 0 Avaya Voice Portal 4.1 Avaya Voice Portal 4.0 Avaya Voice Portal 3.0 Avaya Proactive Contact 4.0 Avaya Proactive Contact 3.0 Avaya Proactive Contact 0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 4.0 Avaya Messaging Storage Server 3.1 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Message Networking MN 3.1 Avaya Message Networking 3.1 Avaya Message Networking Avaya Meeting Exchange - Enterprise Edition Avaya Meeting Exchange 5.0 .0.52 Avaya Meeting Exchange 5.0 Avaya Intuity AUDIX LX 2.0 Avaya Intuity AUDIX Avaya EMMC 1.021 Avaya EMMC 1.017 Avaya EMMC 0 Avaya Communication Manager 4.0.3 SP1 Avaya Communication Manager 3.1.4 SP2 Avaya Communication Manager 2.0.1 Avaya Communication Manager 2.0 Avaya Communication Manager 1.3.1 Avaya Communication Manager 1.1 Avaya Communication Manager 5.1 Avaya Communication Manager 5.0 SP3 Avaya Communication Manager 5.0 Avaya Communication Manager 4.0 Avaya Communication Manager 3.1 Avaya Communication Manager 3.0 Avaya Communication Manager 2.2 Avaya Communication Manager 2.1 Avaya Aura SIP Enablement Services 5.0 Avaya Aura Application Enablement Services 4.2.1 Avaya Aura Application Enablement Services 3.1.6 |
| Not Vulnerable: | |
Discussion
Red Hat OpenSSH Backdoor Vulnerability
OpenSSH running on Red Hat operating systems are prone to a backdoor vulnerability.
Attackers can exploit this issue by enticing an unsuspecting victim to download and install a malicious OpenSSH package from a compromised Red Hat software repository or from mirrors that replicated the malicious packages. Successfully exploiting this issue will compromise the affected computer.
This issue affects OpenSSH running on the following operating systems:
Red Hat Enterprise Linux 4 i386
Red Hat Enterprise Linux 4 x86_64
Red Hat Enterprise Linux 5 x86_64
OpenSSH running on Red Hat operating systems are prone to a backdoor vulnerability.
Attackers can exploit this issue by enticing an unsuspecting victim to download and install a malicious OpenSSH package from a compromised Red Hat software repository or from mirrors that replicated the malicious packages. Successfully exploiting this issue will compromise the affected computer.
This issue affects OpenSSH running on the following operating systems:
Red Hat Enterprise Linux 4 i386
Red Hat Enterprise Linux 4 x86_64
Red Hat Enterprise Linux 5 x86_64
Exploit / POC
Red Hat OpenSSH Backdoor Vulnerability
Attackers can exploit this issue by enticing an unsuspecting to download and install a malicious OpenSSH package from the Red Hat software repository or from mirrors that replicate the malicious package.
Attackers can exploit this issue by enticing an unsuspecting to download and install a malicious OpenSSH package from the Red Hat software repository or from mirrors that replicate the malicious package.
Solution / Fix
Red Hat OpenSSH Backdoor Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
Red Hat OpenSSH Backdoor Vulnerability
References:
References:
- Infrastructure report, 2008-08-22 UTC 1200 (Red Hat)
- OpenSSH Homepage (OpenSSH)
- ASA-2008-399 - openssh security update (RHSA-2008-0855) (Avaya)
- RHSA-2008:0855-6 Critical: openssh security update (Red Hat)