Bug#736066: A number of EncFS issues

2014-05-14 Thread cve-assign
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 https://defuse.ca/audits/encfs.htm the last one sounds CVE worthy Use CVE-2014-3462 for that issue, i.e., 'The purpose of MAC headers is to prevent an attacker with read/write access to the ciphertext from being able to make changes without being

Bug#736066: A number of EncFS issues

2014-05-13 Thread Murray McAllister
Hi, https://defuse.ca/audits/encfs.htm discusses a number of issues in EncFS: Same Key Used for Encryption and Authentication Stream Cipher Used to Encrypt Last File Block Generating Block IV by XORing Block Number File Holes are Not Authenticated MACs Not Compared in Constant Time 64-bit