High severity7.5NVD Advisory· Published Jun 19, 2020· Updated Jun 17, 2026
CVE-2020-14929
CVE-2020-14929
Description
Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- Alpine/Alpinedescription
- osv-coords2 versionspkg:rpm/opensuse/alpine&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/alpine&distro=SUSE%20Package%20Hub%2015%20SP2
< 2.24-lp152.5.3.1+ 1 more
- (no CPE)range: < 2.24-lp152.5.3.1
- (no CPE)range: < 2.24-bp152.4.3.1
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- mailman13.u.washington.edu/pipermail/alpine-info/2020-June/008989.htmlnvdPatchThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/06/msg00025.htmlnvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YFXQGKZZMP3VSTLZVO5Z7Z6USYIW37A6/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZJLY6JDVGDNAJZ3UQDWYWSDBWOAOXMNX/nvd
News mentions
0No linked articles in our index yet.