CVE-2010-3073
Summary
| CVE | CVE-2010-3073 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-09-17 18:00:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | SSL_Cipher.cpp in EncFS before 1.7.0 does not properly handle integer data sizes when constructing headers intended for randomization of initialization vectors, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 13 Update: fuse-encfs-1.7.2-1.fc13 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| oss-security - CVE Request -- EncFS / fuse-encfs [three ids] -- Multiple Vulnerabilities in EncFS | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Bug 630460 – CVE-2010-3073 CVE-2010-3074 CVE-2010-3075 fuse-encfs: EncFS: Multiple flaws | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Fedora update for fuse-encfs - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| [SECURITY] Fedora 14 Update: fuse-encfs-1.7.2-1.fc14 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| EncFS Multiple Weaknesses - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| NEOHAPSIS - Peace of Mind Through Integrity and Insight | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| oss-security - Re: CVE Request -- EncFS / fuse-encfs [three ids] -- Multiple Vulnerabilities in EncFS | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2010:023 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| r59 - encfs - Encrypted Filesystem for FUSE - Google Project Hosting | af854a3a-2127-422b-91ae-364da2661108 | code.google.com | |
| [SECURITY] Fedora 12 Update: fuse-encfs-1.7.2-1.fc12 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| oss-security - Re: CVE Request -- EncFS / fuse-encfs [three ids] -- Multiple Vulnerabilities in EncFS | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.