Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated peers to cause a denial of service (crash) or possibly execute arbitrary code via a large TCP packet.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-04-26 09:55
Updated : 2013-11-30 20:26
NVD link : CVE-2013-1428
Mitre link : CVE-2013-1428
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
tinc-vpn
- tinc