CVE-2018-16758 on Ubuntu 14.04 LTS (trusty) - medium.
Description:
Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets. Prevent a MITM from forcing a NULL cipher for UDP