GHSA-52r2-7jx8-c8gcMediumCVSS 6.5

The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows...

Published
May 17, 2022
Last Modified
May 28, 2026

🔗 CVE IDs covered (1)

📋 Description

The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.

🔗 References (18)