tinc 1.0pre3 and 1.0pre4 VPN does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on CBC.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/249142 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/7868 | vdb entry |