Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.
| Software | From | Fixed in |
|---|---|---|
| alpine_project / alpine | - | 2.23 |
| fedoraproject / fedora | 31 | 31.x |
| fedoraproject / fedora | 32 | 32.x |
| debian / debian_linux | 8.0 | 8.0.x |