CVE-2014-2653

The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.

medium 6.5 CVSS 3.1
Published: Mar 27, 2014
Modified: May 28, 2026
Vendor: Openbsd
Product: Openssh
Versions: 6.0,6.1,6.2,6.3,6.4,6.5

Description

The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.

References

Related CVEs