Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-2653

Опубликовано: 27 мар. 2014
Источник: nvd
CVSS2: 5.8
EPSS Низкий

Описание

The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
Версия до 6.6 (включая)
cpe:2.3:a:openbsd:openssh:6.0:*:*:*:*:*:*:*
cpe:2.3:a:openbsd:openssh:6.1:*:*:*:*:*:*:*
cpe:2.3:a:openbsd:openssh:6.2:*:*:*:*:*:*:*
cpe:2.3:a:openbsd:openssh:6.3:*:*:*:*:*:*:*
cpe:2.3:a:openbsd:openssh:6.4:*:*:*:*:*:*:*
cpe:2.3:a:openbsd:openssh:6.5:*:*:*:*:*:*:*

EPSS

Процентиль: 82%
0.01872
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 11 лет назад

The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.

redhat
больше 11 лет назад

The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.

debian
больше 11 лет назад

The verify_host_key function in sshconnect.c in the client in OpenSSH ...

github
больше 3 лет назад

The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.

oracle-oval
больше 10 лет назад

ELSA-2015-0425: openssh security, bug fix and enhancement update (MODERATE)

EPSS

Процентиль: 82%
0.01872
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-20