Candidate: CVE-2014-3462 PublicDate: 2017-08-07 20:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3462 https://defuse.ca/audits/encfs.htm http://www.openwall.com/lists/oss-security/2014/05/14/2 Description: The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and adding 8 to "blockMACRandBytes". Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=736066 Priority: high Discovered-by: Taylor Hornby Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_encfs: upstream_encfs: released (1.8.1-1) lucid_encfs: ignored (reached end-of-life) precise_encfs: ignored (reached end-of-life) precise/esm_encfs: DNE (precise was needed) quantal_encfs: ignored (reached end-of-life) saucy_encfs: ignored (reached end-of-life) trusty_encfs: ignored (reached end-of-life) trusty/esm_encfs: DNE (trusty was needed) utopic_encfs: ignored (reached end-of-life) vivid_encfs: ignored (reached end-of-life) vivid/stable-phone-overlay_encfs: DNE vivid/ubuntu-core_encfs: DNE wily_encfs: ignored (reached end-of-life) xenial_encfs: not-affected (1.8.1-3) yakkety_encfs: ignored (reached end-of-life) zesty_encfs: ignored (reached end-of-life) artful_encfs: ignored (reached end-of-life) bionic_encfs: not-affected (1.8.1-3) cosmic_encfs: not-affected (1.8.1-3) disco_encfs: not-affected (1.8.1-3) devel_encfs: not-affected (1.8.1-3)