CVE-2018-16738: Medium severity tinc vpn vulnerability
Published Oct 10, 2018
·Updated
tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed in 1.1.
Affected Software
5 affected componentsFixes available
debian/tinc
1.0.35-21.0.36-2
Tinc-vpn Tinc>=1.0.30<=1.0.34
Debian Debian Linux=9.0
Starwindsoftware Starwind Virtual San Vsphere=v8-build12533
Starwindsoftware Starwind Virtual San Vsphere=v8-build12658
Event History
Oct 10, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-16738.
2
What is the severity of CVE-2018-16738?
The severity of CVE-2018-16738 is medium, with a CVSS score of 3.7.
3
What is the affected software and versions?
The affected software is tinc VPN versions 1.0.30 through 1.0.34, Debian Linux version 9.0, Starwind Virtual SAN versions v8-build12533 and v8-build12658.
4
Is there a partial mitigation for CVE-2018-16738?
Yes, there is a partial mitigation for CVE-2018-16738.
5
How is CVE-2018-16738 fixed?
CVE-2018-16738 is fixed in tinc VPN version 1.1.