|
|
| |
|
| |
dar: weak cryptography
| Package(s): | dar |
CVE #(s): | CVE-2007-3528
|
| Created: | July 6, 2007 |
Updated: | July 11, 2007 |
| Description: |
From the National
Vulnerability Database: "The blowfish mode in DAR before 2.3.4
uses weak Blowfish-CBC cryptography by (1) discarding random bits by the
blowfish::make_ivec function in libdar/crypto.cpp that results in
predictable and repeating IV values, and (2) direct use of a password for
keying, which makes it easier for context-dependent attackers to decrypt
files." |
| Alerts: |
|
( Log in to post comments)
|
|
|