Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Debian: DLA-1539-1 Moderate Security Flaw in Tinc and Encryption Issue

debian lts
Calendar Grey October 8, 2018
Scroller Debian Lts
Package : tinc Version : 1.0.24-2+deb8u1 CVE ID : CVE-2018-16737 CVE-2018-16758 Several vulnerabilit
Several vulnerabilities were discovered in tinc, a Virtual Private Network (VPN) daemon

Summary

Michael Yonli discovered a flaw in the implementation of the
authentication protocol that could allow a remote attacker to
establish an authenticated, one-way connection with another node.

CVE-2018-16758

Michael Yonli discovered that a man-in-the-middle that has
intercepted a TCP connection might be able to disable encryption of
UDP packets sent by a node.

For Debian 8 "Jessie", these problems have been fixed in version
1.0.24-2+deb8u1.

We recommend that you upgrade your tinc packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

--
Met vriendelijke groet / with kind regards,
Guus Sliepen


Severity
important
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: tinc
Version: 1.0.24-2+deb8u1
CVE ID: CVE-2018-16737 CVE-2018-16758

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.