CVE Vulnerabilities

CVE-2010-3074

Published: Sep 17, 2010 | Modified: Jan 14, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

SSL_Cipher.cpp in EncFS before 1.7.0 uses an improper combination of an AES cipher and a CBC cipher mode for encrypted filesystems, which allows local users to obtain sensitive information via a watermark attack.

Affected Software

Name Vendor Start Version End Version
Encfs Arg0 * 1.6.0 (including)
Encfs Arg0 1.4.0 (including) 1.4.0 (including)
Encfs Arg0 1.4.1 (including) 1.4.1 (including)
Encfs Arg0 1.4.1.1 (including) 1.4.1.1 (including)
Encfs Arg0 1.4.2 (including) 1.4.2 (including)
Encfs Arg0 1.5.0 (including) 1.5.0 (including)
Encfs Ubuntu artful *
Encfs Ubuntu dapper *
Encfs Ubuntu hardy *
Encfs Ubuntu jaunty *
Encfs Ubuntu karmic *
Encfs Ubuntu lucid *
Encfs Ubuntu maverick *
Encfs Ubuntu natty *
Encfs Ubuntu oneiric *
Encfs Ubuntu precise *
Encfs Ubuntu quantal *
Encfs Ubuntu raring *
Encfs Ubuntu saucy *
Encfs Ubuntu upstream *
Encfs Ubuntu utopic *
Encfs Ubuntu vivid *
Encfs Ubuntu wily *
Encfs Ubuntu yakkety *
Encfs Ubuntu zesty *

References