Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 28: FEDORA-2018-31c2a0b2ea Critical: Tinc Security Fix

fedora
Calendar Grey December 27, 2018
Dist Fedora Esm H88
A security update addressing various CVEs in the tinc VPN for Fedora 28 mitigates severe networking flaws.
Security fix for CVE-2018-16737, CVE-2018-16738, CVE-2018-16758

Summary

tinc is a Virtual Private Network (VPN) daemon that uses tunnelling

and encryption to create a secure private network between hosts on

the Internet. Because the tunnel appears to the IP level network

code as a normal network device, there is no need to adapt any

existing software. This tunnelling allows VPN sites to share

information with each other over the Internet without exposing any

information to others.

Security fix for CVE-2018-16737, CVE-2018-16738, CVE-2018-16758

* Tue Dec 18 2018 Fabian Affolter - 1.0.35-1

- Fix for CVE-2018-16737, CVE-2018-16738 and CVE-2018-16758

- Update to new upstream version 1.0.35

* Fri Oct 26 2018 Fabian Affolter - 1.0.34-1

- Update to new upstream version 1.0.34

* Sat Jul 14 2018 Fedora Release Engineering - 1.0.33-4

- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild

* Thu Mar 8 2018 Fabian Affolter - 1.0.33-3

- Fix BR

[ 1 ] Bug #1637483 - CVE-2018-16737 CVE-2018-16738 CVE-2018-16758 tinc: Multiple issues fixed in the 1.0.35 release [epel-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1637483

[ 2 ] Bug #1637482 - CVE-2018-16737 CVE-2018-16738 CVE-2018-16758 tinc: Multiple issues fixed in the 1.0.35 release [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1637482

su -c 'dnf upgrade --advisory FEDORA-2018-31c2a0b2ea' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 28
Version: 1.0.35
Release: 1.fc28
Summary: A virtual private network daemon

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here