← Back

Tinc Vpn

tinc-vpn

4 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Tinc
tinc

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
StarwindsoftwareTinc Vpn
3Debian Linux
Starwind Virtual SanTinc
Nov 21, 2024
Oct 10, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.
3Debian
StarwindsoftwareTinc Vpn
3Debian Linux
Starwind Virtual SanTinc
Nov 21, 2024
Oct 10, 2018
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed in 1.1.
2Starwindsoftware
Tinc Vpn
2Starwind Virtual San
Tinc
Nov 21, 2024
Oct 10, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.
1Tinc Vpn
1Tinc
Apr 29, 2026
Apr 26, 2013
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated peers to cause a denial of service (crash) or possibly execute arbitr...Show more
Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated peers to cause a denial of service (crash) or possibly execute arbitrary code via a large TCP packet.Show less