Input validation error in OpenSSH - CVE-2014-2653

 

Input validation error in OpenSSH - CVE-2014-2653

Published: March 27, 2014 / Updated: August 3, 2020


Vulnerability identifier: #VU33294
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2014-2653
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
OpenSSH
Software vendor:
OpenSSH

Description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.


Remediation

Install update from vendor's website.

External links