Information disclosure - CVE-2020-14929
Published: June 19, 2020 / Updated: August 3, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.
Affected software
alpine (Alpine package)
alpine
Fedora
How to mitigate CVE-2020-14929
alpine - addressed in versions 2.23-2.el7, 2.23-2.el8, 2.23-2.fc31, 2.23-2.fc32
External References
- http://mailman13.u.washington.edu/pipermail/alpine-info/2020-June/008989.html
- https://lists.debian.org/debian-lts-announce/2020/06/msg00025.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YFXQGKZZMP3VSTLZVO5Z7Z6USYIW37A6/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZJLY6JDVGDNAJZ3UQDWYWSDBWOAOXMNX/