CVE-2018-16758: Medium severity tinc vpn vulnerability
Published Oct 10, 2018
·Updated
Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.
Affected Software
5 affected componentsFixes available
debian/tinc
1.0.35-21.0.36-2
Tinc-vpn Tinc<=1.0.34
Debian Debian Linux=9.0
Starwindsoftware Starwind Virtual San Vsphere=v8-build12533
Starwindsoftware Starwind Virtual San Vsphere=v8-build12658
Event History
Oct 10, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-16758?
CVE-2018-16758 is a vulnerability in Tinc VPN version 1.0.34 and earlier that allows a man-in-the-middle attack to disable VPN packet encryption.
2
What is the severity of CVE-2018-16758?
The severity of CVE-2018-16758 is medium with a severity value of 5.9.
3
How does CVE-2018-16758 affect Tinc VPN?
CVE-2018-16758 affects Tinc VPN version 1.0.34 and earlier by allowing a man-in-the-middle attack to disable packet encryption.
4
How can I fix CVE-2018-16758?
To fix CVE-2018-16758, update Tinc VPN to version 1.0.35-2 or 1.0.36-2.
5
Where can I find more information about CVE-2018-16758?
More information about CVE-2018-16758 can be found at the following references: [1] [2] [3].