CVE-2017-3204
04.04.2017, 14:59
The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4e2799 to require explicitly registering a hostkey verification mechanism.Enginsight
| Vendor | Product | Version |
|---|---|---|
| golang | crypto | 𝑥 ≤ 2017-03-17 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| golang-go.crypto |
| ||||||||||||||||||||||||||||||||||||||
| snapd |
| ||||||||||||||||||||||||||||||||||||||
| ubuntu-snappy |
|
Common Weakness Enumeration
References