CVE-2013-1428
CVE-2013-1428
Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated peers to cause a denial of service (crash) or possibly execute arbitrary code via a large TCP packet.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/35441unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://freecode.com/projects/tinc/releases/354122http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105531.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/105559.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/106167.htmlhttp://osvdb.org/92653http://secunia.com/advisories/53087http://secunia.com/advisories/53108https://github.com/gsliepen/tinc/commit/17a33dfd95b1a29e90db76414eb9622df9632320http://www.debian.org/security/2013/dsa-2663http://www.securityfocus.com/bid/59369http://www.tinc-vpn.org/news/http://www.tinc-vpn.org/pipermail/tinc/2013-April/003240.html