5
CVSSv2

CVE-2020-14929

Published: 19/06/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Alpine prior to 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

alpine project alpine

fedoraproject fedora 31

fedoraproject fedora 32

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #963179 alpine: CVE-2020-14929 Package: src:alpine; Maintainer for src:alpine is Asheesh Laroia <asheesh@asheeshorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 20 Jun 2020 05:48:02 UTC Severity: important Tags: security, upstream Found in versions alpine/220+dfsg1-7, ...