CVE Vulnerabilities

CVE-2020-14929

Published: Jun 19, 2020 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.

Affected Software

Name Vendor Start Version End Version
Alpine Alpine_project * 2.23 (excluding)
Alpine Ubuntu bionic *
Alpine Ubuntu devel *
Alpine Ubuntu eoan *
Alpine Ubuntu esm-apps/bionic *
Alpine Ubuntu esm-apps/focal *
Alpine Ubuntu esm-apps/xenial *
Alpine Ubuntu focal *
Alpine Ubuntu groovy *
Alpine Ubuntu hirsute *
Alpine Ubuntu impish *
Alpine Ubuntu jammy *
Alpine Ubuntu kinetic *
Alpine Ubuntu lunar *
Alpine Ubuntu mantic *
Alpine Ubuntu noble *
Alpine Ubuntu oracular *
Alpine Ubuntu trusty *
Alpine Ubuntu upstream *
Alpine Ubuntu xenial *

References