Early Access — Mondoo Vulnerability Intelligence is currently in preview.
Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk discovered that LXD incorrectly handled the handshake phase and the use of sequence numbers in SSH Binary Packet Protocol (BPP). If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to bypass integrity checks.
2.0.11-0ubuntu1~16.04.4+esm13.0.3-0ubuntu1~18.04.2+esm1