When a libcurl-based application performs transfers via SCP:// or SFTP:// and utilizes the CURLOPT_SSH_KEYFUNCTION callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the known_hosts file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.
7.81.0-1ubuntu1.258.5.0-2ubuntu10.108.14.1-2ubuntu1.48.18.0-1ubuntu2.2Exploitability
AV:NAC:HPR:NUI:NScope
S:UImpact
C:HI:HA:NCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N