CVE-2010-3073
SSL_Cipher.cpp in EncFS before 1.7.0 does not properly handle integer data sizes when constructing headers intended for randomization of initialization vectors, which makes it easier for local users to obtain sensitive information by defeating…
Does this matter?
Lower severity and a low EPSS score (0.71%). Track it; it rarely justifies an emergency change on its own.
Description
SSL_Cipher.cpp in EncFS before 1.7.0 does not properly handle integer data sizes when constructing headers intended for randomization of initialization vectors, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.71% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- arg0/encfs
- Source
- secalert@redhat.com
References
- http://archives.neohapsis.com/archives/fulldisclosure/2010-08/0316.html
- http://code.google.com/p/encfs/source/detail?r=59
- http://lists.fedoraproject.org/pipermail/package-announce/2010-September/047794.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-September/047798.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-September/047825.html
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html
- http://secunia.com/advisories/41158Vendor Advisory
- http://secunia.com/advisories/41478Vendor Advisory
- http://www.openwall.com/lists/oss-security/2010/09/05/3
- http://www.openwall.com/lists/oss-security/2010/09/06/1
- http://www.openwall.com/lists/oss-security/2010/09/07/8
- http://www.vupen.com/english/advisories/2010/2414Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=630460
- http://archives.neohapsis.com/archives/fulldisclosure/2010-08/0316.html
- http://code.google.com/p/encfs/source/detail?r=59
- http://lists.fedoraproject.org/pipermail/package-announce/2010-September/047794.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-September/047798.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-September/047825.html
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html
- http://secunia.com/advisories/41158Vendor Advisory
- http://secunia.com/advisories/41478Vendor Advisory
- http://www.openwall.com/lists/oss-security/2010/09/05/3
- http://www.openwall.com/lists/oss-security/2010/09/06/1
- http://www.openwall.com/lists/oss-security/2010/09/07/8
- http://www.vupen.com/english/advisories/2010/2414Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=630460
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.