CVE Vulnerabilities

CVE-2010-3073

Published: Sep 17, 2010 | Modified: Jan 14, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

SSL_Cipher.cpp in EncFS before 1.7.0 does not properly handle integer data sizes when constructing headers intended for randomization of initialization vectors, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms.

Affected Software

Name Vendor Start Version End Version
Encfs Arg0 * 1.6.0 (including)
Encfs Arg0 1.4.0 (including) 1.4.0 (including)
Encfs Arg0 1.4.1 (including) 1.4.1 (including)
Encfs Arg0 1.4.1.1 (including) 1.4.1.1 (including)
Encfs Arg0 1.4.2 (including) 1.4.2 (including)
Encfs Arg0 1.5.0 (including) 1.5.0 (including)
Encfs Ubuntu dapper *
Encfs Ubuntu hardy *
Encfs Ubuntu jaunty *
Encfs Ubuntu karmic *
Encfs Ubuntu lucid *
Encfs Ubuntu maverick *
Encfs Ubuntu upstream *

References