This is a potential security issue, you are being redirected to http://nvd.nist.gov
Last updated: 11/28/2014 1:10:08 PM
CVE Publication rate: 17.63
NVD provides four mailing lists to the public. For information and subscription instructions please visit
NVD Mailing Lists
Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externally introduced modification (Trojan Horse) that allows the package authors to have an unknown impact. NOTE: since the malicious packages were not distributed from any official Red Hat sources, the scope of this issue is restricted to users who may have obtained these packages through unofficial distribution points. As of 20080827, no unofficial distributions of this software are known.
This alert is primarily for those who may obtain Red Hat binary
packages via channels other than those of official Red Hat subscribers. Packages obtained by Red Hat Enterprise Linux subscribers via Red Hat Network are not at risk.
Redhat has provided a shell script which lists the affected packages and can verify that none of them are installed on a system at the following location:
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because
they may have information that would be of interest to you. No inferences should be drawn on account of other sites
being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose.
NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further,
NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about
this page to email@example.com.
& Privacy Statement / Security Notice
Send comments or suggestions to firstname.lastname@example.org
NIST is an Agency of the U.S. Department of Commerce
Full vulnerability listing