Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.
{ "ubuntu_priority": "medium" }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "tinc", "binary_version": "1.0.35-2build1" }, { "binary_name": "tinc-dbgsym", "binary_version": "1.0.35-2build1" } ] }