CVE-2014-3462: Infoleak
A number of issues were found in the cryptography practices of EncFS. These are detailed in the following audit:
https://defuse.ca/audits/encfs.htm
It also notes some of the issues in bug 630460 may not be fixed correctly.
A fix is currently not available. Fedora and EPEL use a 1.x version. A future 2.0 release may correct these issues: https://code.google.com/p/encfs/issues/detail?id=186
Other sources
The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and adding 8 to "blockMACRandBytes".
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3462?
CVE-2014-3462 is considered to have a critical severity due to significant cryptographic flaws.
How do I fix CVE-2014-3462?
To address CVE-2014-3462, it is recommended to upgrade to EncFS version 1.7.6 or later.
What software is affected by CVE-2014-3462?
CVE-2014-3462 affects versions of EncFS up to 1.7.5 and specific versions of openSUSE such as 13.2, 42.1, and 42.2.
Is CVE-2014-3462 a known vulnerability?
Yes, CVE-2014-3462 is a known vulnerability documented in various security audits and reports.
What are the implications of CVE-2014-3462?
The implications of CVE-2014-3462 include potential unauthorized data access due to weak cryptographic practices.