// For flags

CVE-2010-3075

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

EncFS before 1.7.0 encrypts multiple blocks by means of the CFB cipher mode with the same initialization vector, which makes it easier for local users to obtain sensitive information via calculations involving recovery of XORed data, as demonstrated by an attack on encrypted data in which the last block contains only one byte.

EncFS anterior a v1.7.0 cifra varios bloques a través de el modo de cifrado CFB con el mismo vector de inicialización, lo cual hace más fácil para los usuarios locales obtener información sensible a través de los cálculos relativos a la recuperación de los datos XOR, como lo demuestra un ataque a los datos cifrados en el que el último bloque sólo contiene un byte.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-08-20 CVE Reserved
  • 2010-09-17 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-310: Cryptographic Issues
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Arg0
Search vendor "Arg0"
Encfs
Search vendor "Arg0" for product "Encfs"
<= 1.6.0
Search vendor "Arg0" for product "Encfs" and version " <= 1.6.0"
-
Affected
Arg0
Search vendor "Arg0"
Encfs
Search vendor "Arg0" for product "Encfs"
1.4.0
Search vendor "Arg0" for product "Encfs" and version "1.4.0"
-
Affected
Arg0
Search vendor "Arg0"
Encfs
Search vendor "Arg0" for product "Encfs"
1.4.1
Search vendor "Arg0" for product "Encfs" and version "1.4.1"
-
Affected
Arg0
Search vendor "Arg0"
Encfs
Search vendor "Arg0" for product "Encfs"
1.4.1.1
Search vendor "Arg0" for product "Encfs" and version "1.4.1.1"
-
Affected
Arg0
Search vendor "Arg0"
Encfs
Search vendor "Arg0" for product "Encfs"
1.4.2
Search vendor "Arg0" for product "Encfs" and version "1.4.2"
-
Affected
Arg0
Search vendor "Arg0"
Encfs
Search vendor "Arg0" for product "Encfs"
1.5.0
Search vendor "Arg0" for product "Encfs" and version "1.5.0"
-
Affected