[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.7] tinc: Multiple issues (CVE-2018-16737, CVE-2018-16738, CVE-2018-16758)

ID: oval:org.secpod.oval:def:1801315Date: (C)2019-03-05   (M)2023-11-10
Class: PATCHFamily: unix




CVE-2018-16737: tinc 1.0.29 and earlier allow an oracle attack that could allow a remote attacker to establish one-way communication with a tinc node, allowing it to send fake control messages and inject packets into the VPN. The attack takes only a few seconds to complete. Tinc 1.1pre14 and earlier allow the same attack if they are configured to allow connections from nodes using the legacy 1.0.x protocol. Fixed In Version:¶ tinc 1.0.35

Platform:
Alpine Linux 3.7
Product:
tinc
Reference:
9841
CVE-2018-16737
CVE-2018-16738
CVE-2018-16758
CVE    3
CVE-2018-16738
CVE-2018-16758
CVE-2018-16737
CPE    6
cpe:/o:alpinelinux:alpine_linux:3.7
cpe:/a:tinc-vpn:tinc:1.0.18
cpe:/a:tinc-vpn:tinc:1.0.17
cpe:/a:tinc-vpn:tinc:1.0.19
...

© SecPod Technologies