Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in Alpine.. ========================================================================== Ubuntu Security Notice USN-7360-1 March 20, 2025 alpine vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Alpine. Software Description: - alpine: Text-based email client, friendly for novices but powerful Details: It was discovered that Alpine did not use a secure connection under certain circumstances. A remote attacker could possibly use this issue to leak sensitive information. (CVE-2020-14929) It was discovered that Alpine could allow untagged responses from an IMAP server before upgrading to a TLS connection. A remote attacker could possibly use this issue to leak sensitive information. (CVE-2021-38370) It was discovered that Alpine could crash when receiving certain SMTP commands. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2021-46853) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS alpine 2.22+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro alpine-pico 2.22+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro pilot 2.22+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS alpine 2.21+dfsg1-1ubuntu0.1~esm1 Availablewith Ubuntu Pro alpine-pico 2.21+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro pilot 2.21+dfsg1-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS alpine 2.20+dfsg1-2ubuntu0.1~esm1 Available with Ubuntu Pro alpine-pico 2.20+dfsg1-2ubuntu0.1~esm1 Available with Ubuntu Pro pilot 2.20+dfsg1-2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7360-1 CVE-2020-14929, CVE-2021-38370, CVE-2021-46853 . Several security issues for Alpine users on Ubuntu resolved in the latest advisory; critical updates recommended now.. security, alpine, ======================================================. . Severity: Important. LinuxSecurity.com Team
Multiple vulnerabilities have been found in Alpine, the worst of which could result in denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202301-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Alpine: Multiple Vulnerabilities Date: January 11, 2023 Bugs: #807613 ID: 202301-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Alpine, the worst of which could result in denial of service. Background ========= Alpine is an easy to use text-based based mail and news client. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-client/alpine < 2.25 > = 2.25 Description ========== Multiple vulnerabilities have been discovered in Alpine. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Alpine users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-client/alpine-2.25" References ========= [ 1 ] CVE-2021-38370 https://nvd.nist.gov/vuln/detail/CVE-2021-38370 [ 2 ] CVE-2021-46853 https://nvd.nist.gov/vuln/detail/CVE-2021-46853 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202301-07 Concerns? ======== Security is a primary focus of Gentoo Linux andensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
New alpine packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] alpine (SSA:2021-264-01) New alpine packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/alpine-2.25-i586-1_slack14.2.txz: Upgraded. Fixed a denial-of-service security issue where untagged responses from an IMAP server are accepted before STARTTLS. For more information, see: https://www.cve.org/CVERecord?id=CVE-2021-38370 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.0: ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/alpine-2.25-i486-1_slack14.0.txz Updated package for Slackware x86_64 14.0: ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/alpine-2.25-x86_64-1_slack14.0.txz Updated package for Slackware 14.1: ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/alpine-2.25-i486-1_slack14.1.txz Updated package for Slackware x86_64 14.1: ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/alpine-2.25-x86_64-1_slack14.1.txz Updated package for Slackware 14.2: ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/alpine-2.25-i586-1_slack14.2.txz Updated package for Slackware x86_64 14.2: ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/alpine-2.25-x86_64-1_slack14.2.txz Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.0package: dc6c6e654668335fe8c5366ad22ca646 alpine-2.25-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 03e723d22b7b6e2f6014cb205582a600 alpine-2.25-x86_64-1_slack14.0.txz Slackware 14.1 package: d5163aee83e992f3d6dbd13af5a64055 alpine-2.25-i486-1_slack14.1.txz Slackware x86_64 14.1 package: 89339d7df6a25407268ec4123e59cb09 alpine-2.25-x86_64-1_slack14.1.txz Slackware 14.2 package: 1131bff5cac947b879c4d000828e3f51 alpine-2.25-i586-1_slack14.2.txz Slackware x86_64 14.2 package: e966b110aff7b5b1ba815272ba0a50e7 alpine-2.25-x86_64-1_slack14.2.txz Slackware -current package: 9c46412f5972f758b445ffc02a1a9d4d n/alpine-2.25-i586-1.txz Slackware x86_64 -current package: cf2973e64125079c73b21be89dc46576 n/alpine-2.25-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg alpine-2.25-i586-1_slack14.2.txz +-----+ . Recent updates for alpine packages fix a denial of service vulnerability affecting multiple Slackware releases. Ensure your system is secure by upgrading promptly.. Alpine Package Fix, Slackware Security Update, Denial of Service Issue. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for alpine ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0695-1 Rating: moderate References: #1173281 Cross-References: CVE-2020-14929 CVSS scores: CVE-2020-14929 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2020-14929 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for alpine fixes the following issues: Update to release 2.24 * A few crash fixes * Implementation of XOAUTH2 for Yahoo! Mail. Update to release 2.23.2 * Expansion of the configuration screen for XOAUTH2 to include username, and tenant. * Alpine uses the domain in the From: header of a message to generate a message-id and suppresses all information about Alpine, version, revision, and time of generation of the message-id from this header. * Alpine does not generate Sender or X-X-Sender by default by enabling [X] Disable Sender as the default. * Alpine does not disclose User Agent by default by enabling [X] Suppress User Agent by default. * When messages are selected, pressing the ';' command to broaden or narrow a search, now offers the possibility to completely replace the search, and is almost equivalent to being a shortcut to "unselect all messages, and select again". Update to release 2.23 * Fixes boo#1173281, CVE-2020-14929: Alpine silently proceeds to use an insecure connection after a /tls is sent in certain circumstances. * Implementation of XOAUTH2 authentication support for Outlook. * Add support for the OAUTHBEARER authentication method in Gmail. * Support for the SASL-IR IMAP extension. * Alpine can pass an HTML message to an external web browser, by using the "External" command in the ATTACHMENT INDEX screen. Update to release 2.22 * Support for XOAUTH2 authentication method in Gmail. * NTLM authentication support with the ntlm library. * Added the "/tls1_3" flag for servers that support it. * Add the "g" option to the select command that works in IMAP servers that implement the X-GM-EXT-1 capability (such as the one offered by Gmail). * Added "/auth=XYZ" to the way to define a server. This allows users to select the method to authenticate to an IMAP, SMTP or POP3 server. Examples are /auth=plain, or /auth=gssapi, etc. * When a message is of type multipart/mixed, and its first part is multipart/signed, Alpine will include the text of the original message in a reply message, instead of including a multipart attachment. * Added backward search in the index screen. * pico: Add -dict option to Pico, which allows users to choose a dictionary when spelling. - Drop /usr/bin/mailutil, it is not built by default anymore. * Added Quota subcommands for printing, forwarding, saving, etc. This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2021-695=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64): alpine-2.24-bp152.4.3.1 pico-5.07-bp152.4.3.1 pilot-2.99-bp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2020-14929.html https://bugzilla.suse.com/1173281 . openSUSE Security Patch for alpine: Addresses CVE-2020-14929 and enhances security measures for dependable performance.. openSUSEAlpine Update, Security Update, Insecure Connection Fix. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for alpine ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0675-1 Rating: moderate References: #1173281 Cross-References: CVE-2020-14929 CVSS scores: CVE-2020-14929 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2020-14929 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for alpine fixes the following issues: Update to release 2.24 * A few crash fixes * Implementation of XOAUTH2 for Yahoo! Mail. Update to release 2.23.2 * Expansion of the configuration screen for XOAUTH2 to include username, and tenant. * Alpine uses the domain in the From: header of a message to generate a message-id and suppresses all information about Alpine, version, revision, and time of generation of the message-id from this header. * Alpine does not generate Sender or X-X-Sender by default by enabling [X] Disable Sender as the default. * Alpine does not disclose User Agent by default by enabling [X] Suppress User Agent by default. * When messages are selected, pressing the ';' command to broaden or narrow a search, now offers the possibility to completely replace the search, and is almost equivalent to being a shortcut to "unselect all messages, and select again". Update to release 2.23 * Fixes boo#1173281, CVE-2020-14929: Alpine silently proceeds to use an insecure connection after a /tls is sent in certain circumstances. * Implementation of XOAUTH2 authentication support for Outlook. * Add support for the OAUTHBEARER authentication method in Gmail. * Supportfor the SASL-IR IMAP extension. * Alpine can pass an HTML message to an external web browser, by using the "External" command in the ATTACHMENT INDEX screen. Update to release 2.22 * Support for XOAUTH2 authentication method in Gmail. * NTLM authentication support with the ntlm library. * Added the "/tls1_3" flag for servers that support it. * Add the "g" option to the select command that works in IMAP servers that implement the X-GM-EXT-1 capability (such as the one offered by Gmail). * Added "/auth=XYZ" to the way to define a server. This allows users to select the method to authenticate to an IMAP, SMTP or POP3 server. Examples are /auth=plain, or /auth=gssapi, etc. * When a message is of type multipart/mixed, and its first part is multipart/signed, Alpine will include the text of the original message in a reply message, instead of including a multipart attachment. * Added backward search in the index screen. * pico: Add -dict option to Pico, which allows users to choose a dictionary when spelling. - Drop /usr/bin/mailutil, it is not built by default anymore. * Added Quota subcommands for printing, forwarding, saving, etc. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-675=1 Package List: - openSUSE Leap 15.2 (x86_64): alpine-2.24-lp152.5.3.1 alpine-debuginfo-2.24-lp152.5.3.1 alpine-debugsource-2.24-lp152.5.3.1 pico-5.07-lp152.5.3.1 pico-debuginfo-5.07-lp152.5.3.1 pilot-2.99-lp152.5.3.1 pilot-debuginfo-2.99-lp152.5.3.1 References: https://www.suse.com/security/cve/CVE-2020-14929.html https://bugzilla.suse.com/1173281 . The latest alpine version addresses several notable concerns, such as bug resolutions and enhanced XOAUTH2compatibility for improved secure connections.. openSUSE, Alpine, Security Patch, Moderate Issues, XOAUTH2 Support. . LinuxSecurity.com Team
2.23 fixes CVE-2020-14929 (#1850048,#1850047) and new version (#1848786). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-f822ea9330 2020-07-03 01:36:57.651019 --------------------------------------------------------------------------------Name : alpine Product : Fedora 31 Version : 2.23 Release : 2.fc31 URL : Summary : powerful, easy to use console email client Description : Alpine -- an Alternatively Licensed Program for Internet News & Email -- is a tool for reading, sending, and managing electronic messages. Alpine is the successor to Pine and was developed by Computing & Communications at the University of Washington. Though originally designed for inexperienced email users, Alpine supports many advanced features, and an ever-growing number of configuration and personal-preference options. Changes and enhancements over pine: * Released under the Apache Software License, Version 2.0. * Internationalization built around new internal Unicode support. * Ground-up reorganization of source code around new "pith/" core routine library. * Ground-up reorganization of build and install procedure based on GNU Build System's autotools. --------------------------------------------------------------------------------Update Information: 2.23 fixes CVE-2020-14929 (#1850048,#1850047) and new version (#1848786) --------------------------------------------------------------------------------ChangeLog: * Tue Jun 23 2020 josef radinger - 2.23-2 - 2.23 fixes CVE-2020-14929 (#1850048) and new version (#1848786) * Mon Jun 22 2020 josef radinger - 2.23-1 - bump version - update patch2 alpine-2.23-gcc10.patch * Tue Mar 24 2020 josef radinger - 2.22-1 - bump version * Thu Feb 13 2020 Than Ngo - 2.21-13 - fixed multiple definition of symbols * Tue Jan 28 2020 Fedora Release Engineering - 2.21-12 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1850047 - CVE-2020-14929 alpine: silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH https://bugzilla.redhat.com/show_bug.cgi?id=1850047 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-f822ea9330' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
CVE-2020-14929 Alpine before 2.23 silently proceeds to use an insecure connection . Package : alpine Version : 2.11+dfsg1-3+deb8u1 CVE ID : CVE-2020-14929 Debian Bug : 963179 CVE-2020-14929 Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do. For Debian 8 "Jessie", this problem has been fixed in version 2.11+dfsg1-3+deb8u1. We recommend that you upgrade your alpine packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The latest Alpine 2.11 release addresses vulnerabilities related to CVE-2020-14929, enhancing secure connectivity. Users of Debian 8 should prioritize this upgrade.. Alpine Security Update, CVE-2020-14929 Fix, Debian LTS Advisory. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.