CVE-2010-3074

Severity CVSS v4.0:
Pending analysis
Type:
CWE-310 Cryptographic Issues
Publication date:
17/09/2010
Last modified:
11/04/2025

Description

SSL_Cipher.cpp in EncFS before 1.7.0 uses an improper combination of an AES cipher and a CBC cipher mode for encrypted filesystems, which allows local users to obtain sensitive information via a watermark attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:arg0:encfs:*:*:*:*:*:*:*:* 1.6.0 (including)
cpe:2.3:a:arg0:encfs:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:arg0:encfs:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:arg0:encfs:1.4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:arg0:encfs:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:arg0:encfs:1.5.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools