Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-3204

Опубликовано: 04 апр. 2017
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 6.8
CVSS3: 8.1

Описание

The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4e2799 to require explicitly registering a hostkey verification mechanism.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

1:0.0~git20170629.0.5ef0053-2
cosmic

not-affected

1:0.0~git20180614.a8fb68e-1
devel

not-affected

1:0.0~git20180614.a8fb68e-1
disco

not-affected

1:0.0~git20180614.a8fb68e-1
eoan

not-affected

1:0.0~git20180614.a8fb68e-1
esm-apps/bionic

not-affected

1:0.0~git20170629.0.5ef0053-2
esm-apps/focal

not-affected

1:0.0~git20180614.a8fb68e-1
esm-apps/jammy

not-affected

1:0.0~git20180614.a8fb68e-1
esm-apps/noble

not-affected

1:0.0~git20180614.a8fb68e-1

Показывать по

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support
cosmic

ignored

end of life
devel

ignored

code not used
disco

ignored

end of life
eoan

ignored

end of life
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [code not used]]
esm-infra/bionic

ignored

code not used
esm-infra/focal

ignored

code not used
esm-infra/xenial

ignored

code not used

Показывать по

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

Показывать по

EPSS

Процентиль: 82%
0.01811
Низкий

6.8 Medium

CVSS2

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 4.8
redhat
почти 9 лет назад

The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4e2799 to require explicitly registering a hostkey verification mechanism.

CVSS3: 8.1
nvd
почти 9 лет назад

The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4e2799 to require explicitly registering a hostkey verification mechanism.

CVSS3: 8.1
debian
почти 9 лет назад

The Go SSH library (x/crypto/ssh) by default does not verify host keys ...

CVSS3: 8.1
github
почти 3 года назад

golang.org/x/crypto/ssh Man-in-the-Middle attack

CVSS3: 8.1
fstec
почти 9 лет назад

Уязвимость библиотеки SSH (x/crypto/ssh) языка программирования Go, позволяющая нарушителю выполнить атаку типа «человек посередине»

EPSS

Процентиль: 82%
0.01811
Низкий

6.8 Medium

CVSS2

8.1 High

CVSS3