View at Official debian advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2017-3204 not yet assigned priority: Debian including 1 source packages (golang-go.crypto), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5.
The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4e2799 to require explicitly registering a hostkey verification mechanism.