Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-15079

Опубликовано: 08 янв. 2026
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 5.3

Описание

When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts not present in the specified file if they were added as recognized in the libssh global known_hosts file.

РелизСтатусПримечание
devel

not-affected

code not compiled
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

released

7.58.0-2ubuntu3.24+esm7
esm-infra/focal

released

7.68.0-1ubuntu2.25+esm2
esm-infra/xenial

not-affected

code not present
jammy

released

7.81.0-1ubuntu1.22
noble

released

8.5.0-2ubuntu10.7
plucky

not-affected

code not compiled
questing

not-affected

code not compiled
upstream

released

8.18.0-1

Показывать по

EPSS

Процентиль: 10%
0.00035
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
3 месяца назад

When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.

msrc
3 месяца назад

libssh global known_hosts override

CVSS3: 5.3
debian
3 месяца назад

When doing SSH-based transfers using either SCP or SFTP, and setting t ...

CVSS3: 5.3
github
3 месяца назад

When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.

CVSS3: 5.3
fstec
3 месяца назад

Уязвимость библиотеки libcurl программного средства для взаимодействия с серверами cURL, позволяющая нарушителю оказать воздействие на конфиденциальность защищаемой информации

EPSS

Процентиль: 10%
0.00035
Низкий

5.3 Medium

CVSS3

Уязвимость CVE-2025-15079