ZeroHour

CVE-2020-14929

CVSS 3.1
7.5 high
EPSS
2%p77
Published
()
Modified
Description

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.

Vendors
alpine projectfedoraprojectdebian
Products
alpine, fedora, debian linux
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news