VDB
BDU%3A2025-01959
BDU%3A2025-01959
PUBLISHED
CVSS 7.099999904632568 HIGH
Уязвимость компонента VerifyHostKeyDNS средства криптографической защиты OpenSSH, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)
Risk Scores
CVSS 2.0
7.099999904632568
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Canonical Ltd., Сообщество свободного программного обеспечения, ООО «Ред Софт», ООО «РусБИТех-Астра», Red Hat Inc., Fedora Project, OpenBSD Project, АО "НППКТ" | openSUSE Tumbleweed, Ubuntu, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise Micro, Red Hat OpenShift Container Platform, Red Hat Enterprise Linux, SUSE Manager Retail Branch Server, SUSE Manager Proxy, SUSE Manager Server, SUSE Enterprise Storage, Suse Linux Enterprise Server, SUSE Linux Enterprise High Performance Computing, Astra Linux Common Edition (запись в едином реестре российских программ №4433), Fedora, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Module for Basesystem, OpenSUSE Leap, SUSE Linux Enterprise Module for Desktop Applications, OpenSSH, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913) |
Timeline
- Feb 24, 2025 CVE Published
- Jan 20, 2026 CVE Updated
References
- https://blog.qualys.com/vulnerabilities-threat-research/2025/02/18/qualys-tru-обнаруживает url
- https://bugzilla.redhat.com/show_bug.cgi?id=2344780 url
- https://bugzilla.suse.com/show_bug.cgi?id=1237040 url
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/008_ssh.patch.sig url
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2025-February/000161.html url
- https://seclists.org/oss-sec/2025/q1/144 url
- https://www.openssh.com/releasenotes.html#9.9p2 url
- https://www.openwall.com/lists/oss-security/2025/02/18/1 url
- https://www.openwall.com/lists/oss-security/2025/02/18/4 url
- https://www.theregister.com/2025/02/18/openssh_vulnerabilities_mitm_dos/ url
- https://xakep.ru/2025/02/19/openssh-cves/ url
- https://www.securitylab.ru/news/556556.php url
- https://github.com/rxerium/CVE-2025-26465 url
- https://vuldb.com/?id.296123 url
- https://security-tracker.debian.org/tracker/CVE-2025-26465 url
- https://access.redhat.com/security/cve/CVE-2025-26465 url
- https://ubuntu.com/security/CVE-2025-26465 url
- https://www.suse.com/security/cve/CVE-2025-26465.html url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ENK5YMPKXQSSNGJEVGYMVJ3T3PDA2HDE/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/STTU3AYQZPT4FUMERJH7RQ3KH3TMQDUI/ url
…and 6 more