LWN.net Logo

fuse-encfs: multiple vulnerabilities

Package(s):fuse-encfs CVE #(s):CVE-2010-3073 CVE-2010-3074 CVE-2010-3075
Created:September 22, 2010 Updated:December 8, 2010
Description:

From the Red Hat Bugzilla entry:

Micha Riser reported three security flaws in EncFS encrypted filesystem:

A security analysis of EncFS has revealed multiple vulnerabilities:
(1) Only 32 bit of file IV used
(2) Watermarking attack
(3) Last block with single byte is insecure

Alerts:
SUSE SUSE-SR:2010:023 2010-12-08
openSUSE openSUSE-SU-2010:1028-1 2010-12-07
Fedora FEDORA-2010-14268 2010-09-08
Fedora FEDORA-2010-14254 2010-09-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds