CVE-2010-3075
EPSS 2.1%
Description
EncFS before 1.7.0 encrypts multiple blocks by means of the CFB cipher mode with the same initialization vector, which makes it easier for local users to obtain sensitive information via calculations involving recovery of XORed data, as demonstrated by an attack on encrypted data in which the last block contains only one byte.
How to fix CVE-2010-3075
To remediate CVE-2010-3075, upgrade the affected package to a fixed version below.
- Debian/encfs—upgrade to 1.7.2-1 or later
Is CVE-2010-3075 being exploited?
Low — EPSS is 2.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.7.2-1