Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.
| Software | From | Fixed in |
|---|---|---|
| tinc-vpn / tinc | - | 1.0.34.x |
| debian / debian_linux | 9.0 | 9.0.x |
| starwindsoftware / starwind_virtual_san | 8-build12533 | 8-build12533.x |
| starwindsoftware / starwind_virtual_san | 8-build12658 | 8-build12658.x |