Information disclosure - CVE-2020-14929

 

Information disclosure - CVE-2020-14929

Published: June 19, 2020 / Updated: August 3, 2020


Vulnerability identifier: #VU32981
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14929
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.


Affected software

exiv2 (Alpine package)
alpine (Alpine package)
alpine
Fedora

How to mitigate CVE-2020-14929

Install update from vendor's website.

exiv2 (Alpine package) - update to 0.27.2-r3
alpine - addressed in versions 2.23-2.el7, 2.23-2.el8, 2.23-2.fc31, 2.23-2.fc32

External References

Related Security Bulletins