CVE-2020-14929: High severity alpine vulnerability
Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-14929?
CVE-2020-14929 is a vulnerability in Alpine before version 2.23 that allows for an insecure connection to be used after a /tls is sent in certain circumstances.
What is the severity of CVE-2020-14929?
The severity of CVE-2020-14929 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2020-14929?
Alpine version up to and excluding 2.23, Fedora 31 and 32, and Debian Linux version 8.0 are affected by CVE-2020-14929.
How can I fix CVE-2020-14929?
To fix CVE-2020-14929, update Alpine to version 2.23 or newer, Fedora to a version higher than 32, or Debian Linux to a version higher than 8.0.
Where can I find more information about CVE-2020-14929?
More information about CVE-2020-14929 can be found at the following links: [link1](http://mailman13.u.washington.edu/pipermail/alpine-info/2020-June/008989.html), [link2](https://lists.debian.org/debian-lts-announce/2020/06/msg00025.html), and [link3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YFXQGKZZMP3VSTLZVO5Z7Z6USYIW37A6/).