Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do (CVE-2020-14929). . MGASA-2021-0014 - Updated alpine and c-client packages fix security vulnerability Publication date: 10 Jan 2021 URL: https://advisories.mageia.org/MGASA-2021-0014.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-14929 Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do (CVE-2020-14929). References: - https://bugs.mageia.org/show_bug.cgi?id=26880 - https://lists.debian.org/debian-lts-announce/2020/06/msg00025.html - https://www.cve.org/CVERecord?id=CVE-2020-14929 SRPMS: - 7/core/alpine-2.11-5.1.mga7 - 7/core/c-client-2007f-13.1.mga7 . The recent c-client security patch MGASA-2021-0014 for Alpine addresses vulnerabilities related to connection stability. Stay updated on the applied solutions.. Mageia Security Advisory, Alpine Connection Update, c-client Security Fix. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.