ECHO-06e5-62cc-395f

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-06e5-62cc-395f.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-06e5-62cc-395f
Upstream
  • GHSA-96g2-7cqx-5ggh
Withdrawn
2025-08-03T16:59:07Z
Published
2026-01-29T00:50:47Z
Modified
2026-09-15T03:42:40Z
Summary
This issue has been fixed to the best ability of the maintainers by adjusting host key ordering to always use the default if the client has learned a hostkey matching the best-preference algorithm. Fixes beyond this are considered to reduce overall security by the maintainers. https://security-tracker.debian.org/tracker/CVE-2020-14145 https://docs.ssh-mitm.at/vulnerabilities/CVE-2020-14145.html
Details
References

Affected packages

Echo / openssh

Package

Name
openssh
Purl
pkg:deb/echo/openssh

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1:9.2p1-2+deb12u6

Database specific

source
"https://advisory.echohq.com/osv/ECHO-06e5-62cc-395f.json"