Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security fix for CVE-2018-16737, CVE-2018-16738, CVE-2018-16758. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-afae5e8438 2018-12-28 05:12:22.865851 --------------------------------------------------------------------------------Name : tinc Product : Fedora 29 Version : 1.0.35 Release : 1.fc29 URL : http://www.tinc-vpn.org/ Summary : A virtual private network daemon Description : tinc is a Virtual Private Network (VPN) daemon that uses tunnelling and encryption to create a secure private network between hosts on the Internet. Because the tunnel appears to the IP level network code as a normal network device, there is no need to adapt any existing software. This tunnelling allows VPN sites to share information with each other over the Internet without exposing any information to others. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2018-16737, CVE-2018-16738, CVE-2018-16758 --------------------------------------------------------------------------------ChangeLog: * Tue Dec 18 2018 Fabian Affolter - 1.0.35-1 - Fix for CVE-2018-16737, CVE-2018-16738 and CVE-2018-16758 - Update to new upstream version 1.0.35 * Fri Oct 26 2018 Fabian Affolter - 1.0.34-1 - Update to new upstream version 1.0.34 --------------------------------------------------------------------------------References: [ 1 ] Bug #1637483 - CVE-2018-16737 CVE-2018-16738 CVE-2018-16758 tinc: Multiple issues fixed in the 1.0.35 release [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1637483 [ 2 ] Bug #1637482 - CVE-2018-16737 CVE-2018-16738 CVE-2018-16758 tinc: Multiple issues fixed in the 1.0.35 release [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1637482 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2018-afae5e8438' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2018-16737, CVE-2018-16738, CVE-2018-16758. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-31c2a0b2ea 2018-12-27 01:50:28.953618 --------------------------------------------------------------------------------Name : tinc Product : Fedora 28 Version : 1.0.35 Release : 1.fc28 URL : http://www.tinc-vpn.org/ Summary : A virtual private network daemon Description : tinc is a Virtual Private Network (VPN) daemon that uses tunnelling and encryption to create a secure private network between hosts on the Internet. Because the tunnel appears to the IP level network code as a normal network device, there is no need to adapt any existing software. This tunnelling allows VPN sites to share information with each other over the Internet without exposing any information to others. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2018-16737, CVE-2018-16738, CVE-2018-16758 --------------------------------------------------------------------------------ChangeLog: * Tue Dec 18 2018 Fabian Affolter - 1.0.35-1 - Fix for CVE-2018-16737, CVE-2018-16738 and CVE-2018-16758 - Update to new upstream version 1.0.35 * Fri Oct 26 2018 Fabian Affolter - 1.0.34-1 - Update to new upstream version 1.0.34 * Sat Jul 14 2018 Fedora Release Engineering - 1.0.33-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Thu Mar 8 2018 Fabian Affolter - 1.0.33-3 - Fix BR --------------------------------------------------------------------------------References: [ 1 ] Bug #1637483 - CVE-2018-16737 CVE-2018-16738 CVE-2018-16758 tinc: Multiple issues fixed in the 1.0.35 release [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1637483 [ 2 ] Bug #1637482 - CVE-2018-16737 CVE-2018-16738 CVE-2018-16758 tinc: Multiple issues fixed in the 1.0.35 release [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1637482 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-31c2a0b2ea' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Several vulnerabilities were discovered in tinc, a Virtual Private Network (VPN) daemon. The Common Vulnerabilities and Exposures project identifies the following problems: . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4312-1
Martin Schobert discovered a stack-based vulnerability in tinc, a virtual private network daemon. When packets are forwarded via TCP, packet length is not checked against . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2663-1
Get the latest Linux and open source security news straight to your inbox.