Source: alpine
Version: 2.22+dfsg1-1
Severity: important
Tags: security upstream
Control: found -1 2.21+dfsg1-1.1
Control: found -1 2.20+dfsg1-7

Hi,

The following vulnerability was published for alpine.

CVE-2020-14929[0]:
| Alpine before 2.23 silently proceeds to use an insecure connection
| after a /tls is sent in certain circumstances involving PREAUTH, which
| is a less secure behavior than the alternative of closing the
| connection and letting the user decide what they would like to do.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2020-14929
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14929
[1] 
https://repo.or.cz/alpine.git/commit/000edd9036b6aea5e6a06900ecd6c58faec665ab
[2] 
http://mailman13.u.washington.edu/pipermail/alpine-info/2020-June/008989.html

Regards,
Salvatore

Reply via email to