CVE-2010-3075
 
Severity Score
5.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
EncFS before 1.7.0 encrypts multiple blocks by means of the CFB cipher mode with the same initialization vector, which makes it easier for local users to obtain sensitive information via calculations involving recovery of XORed data, as demonstrated by an attack on encrypted data in which the last block contains only one byte.
EncFS anterior a v1.7.0 cifra varios bloques a través de el modo de cifrado CFB con el mismo vector de inicialización, lo cual hace más fácil para los usuarios locales obtener información sensible a través de los cálculos relativos a la recuperación de los datos XOR, como lo demuestra un ataque a los datos cifrados en el que el último bloque sólo contiene un byte.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2010-08-20 CVE Reserved
- 2010-09-17 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/fulldisclosure/2010-08/0316.html | Mailing List | |
http://www.arg0.net/encfs | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2010/09/05/3 | Mailing List | |
http://www.openwall.com/lists/oss-security/2010/09/06/1 | Mailing List | |
http://www.openwall.com/lists/oss-security/2010/09/07/8 | Mailing List | |
https://bugzilla.redhat.com/show_bug.cgi?id=630460 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Arg0 Search vendor "Arg0" | Encfs Search vendor "Arg0" for product "Encfs" | <= 1.6.0 Search vendor "Arg0" for product "Encfs" and version " <= 1.6.0" | - |
Affected
| ||||||
Arg0 Search vendor "Arg0" | Encfs Search vendor "Arg0" for product "Encfs" | 1.4.0 Search vendor "Arg0" for product "Encfs" and version "1.4.0" | - |
Affected
| ||||||
Arg0 Search vendor "Arg0" | Encfs Search vendor "Arg0" for product "Encfs" | 1.4.1 Search vendor "Arg0" for product "Encfs" and version "1.4.1" | - |
Affected
| ||||||
Arg0 Search vendor "Arg0" | Encfs Search vendor "Arg0" for product "Encfs" | 1.4.1.1 Search vendor "Arg0" for product "Encfs" and version "1.4.1.1" | - |
Affected
| ||||||
Arg0 Search vendor "Arg0" | Encfs Search vendor "Arg0" for product "Encfs" | 1.4.2 Search vendor "Arg0" for product "Encfs" and version "1.4.2" | - |
Affected
| ||||||
Arg0 Search vendor "Arg0" | Encfs Search vendor "Arg0" for product "Encfs" | 1.5.0 Search vendor "Arg0" for product "Encfs" and version "1.5.0" | - |
Affected
|