The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and adding 8 to "blockMACRandBytes".
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade encfs | Jul 30, 2024 | Aug 7, 2017 |
| Gentoo Linux | — | Upgrade sys-fs/encfs. | Oct 30, 2017 | Aug 7, 2017 |
| Suse | — | Upgrade encfs-debuginfoUpgrade encfs-debugsourceUpgrade encfsUpgrade encfs-lang | Jan 17, 2017 | Jan 16, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub