CVE-2010-3073
Publication date 17 September 2010
Last updated 24 July 2024
Ubuntu priority
Description
SSL_Cipher.cpp in EncFS before 1.7.0 does not properly handle integer data sizes when constructing headers intended for randomization of initialization vectors, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms.