The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-2653