Security flaws in tinc

From: Jerome Etienne (jme@off.net)
Date: 01/09/02


Date: Wed, 9 Jan 2002 14:08:39 -0500
From: Jerome Etienne <jme@off.net>
To: bugtraq@securityfocus.com


Hello,

the following text describes security flaws in Tinc. It includes a
description of the security and lists the possible attacks i found.
An attacker can modify packets, replay them and learn pattern of
the plain text. the tinc author confirmed they are real and practical.

ps: version in .ps, .pdf and .html can be found in http://www.off.net/~jme