In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere is no fixed version for quincy
.
quincy is a VPN client and server implementation using the QUIC protocol
Affected versions of this package are vulnerable to Trust Boundary Violation (TunnelVision) in the routing of VPN traffic, when DHCP option 121 is enabled. An attacker on an untrusted network can inject a malicious entry into the victim's routing table which will redirect traffic intended for the VPN to a physical interface handling DHCP.
Methods for avoiding this technique (other than disabling option 121 entirely) depend on the platform on which the application is running. For more detailed recommendations see the TunnelVision publication.