RSS   Vulnerabilities for 'TINC'   RSS

2018-10-10
 
CVE-2018-16758

CWE-306
 

 
Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.

 
 
CVE-2018-16737

CWE-287
 

 
tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.

 
2013-04-26
 
CVE-2013-1428

CWE-119
 

 
Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated peers to cause a denial of service (crash) or possibly execute arbitrary code via a large TCP packet.

 


Copyright 2024, cxsecurity.com

 

Back to Top