Bug#853916: encfs '-S' vulnerability

2017-02-10 Thread Agustin Martin
On Wed, Feb 01, 2017 at 09:36:47PM -0500, David Steele wrote: > Package: encfs > Version: 1.9.1-3 > Severity: serious > thanks > > > Recently, a change in Encfs was found to have broken cryptkeeper, causing it > to use the password 'p' for all operations, regardless of user input > (#852751)[3].

Bug#853916: encfs '-S' vulnerability

2017-02-01 Thread David Steele
Package: encfs Version: 1.9.1-3 Severity: serious thanks Recently, a change in Encfs was found to have broken cryptkeeper, causing it to use the password 'p' for all operations, regardless of user input (#852751)[3]. The bug was closed by removing cryptkeeper from Debian. The issue, however, re