CVE-2002-1755

tinc 1.0pre3 and 1.0pre4 VPN does not authenticate forwarded packets, which allows remote attackers to inject data into user sessions without detection, and possibly control the data contents via cut-and-paste attacks on CBC.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tinc:tinc:1.0pre3:*:*:*:*:*:*:*
cpe:2.3:a:tinc:tinc:1.0pre4:*:*:*:*:*:*:*

History

20 Nov 2024, 23:42

Type Values Removed Values Added
References () http://www.securityfocus.com/archive/1/249142 - () http://www.securityfocus.com/archive/1/249142 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/7868 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/7868 -

Information

Published : 2002-12-31 05:00

Updated : 2024-11-20 23:42


NVD link : CVE-2002-1755

Mitre link : CVE-2002-1755

CVE.ORG link : CVE-2002-1755


JSON object : View

Products Affected

tinc

  • tinc