CVE-2014-2653
27.03.2014, 10:55
The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.Enginsight
| Vendor | Product | Version |
|---|---|---|
| openbsd | openssh | 𝑥 ≤ 6.6 |
| openbsd | openssh | 6.0 |
| openbsd | openssh | 6.1 |
| openbsd | openssh | 6.2 |
| openbsd | openssh | 6.3 |
| openbsd | openssh | 6.4 |
| openbsd | openssh | 6.5 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References