CVE-2017-3204
04.04.2017, 14:59
The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4e2799 to require explicitly registering a hostkey verification mechanism.Enginsight
Vendor | Product | Version |
---|---|---|
golang | crypto | 𝑥 ≤ 2017-03-17 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
golang-go.crypto |
| ||||||||||||||||||||||||||||||||||||||
snapd |
| ||||||||||||||||||||||||||||||||||||||
ubuntu-snappy |
|
Common Weakness Enumeration
References