The verifyhostkey function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.
{ "urgency": "low" }
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2014-2653.json"