SSL_Cipher.cpp in EncFS before 1.7.0 uses an improper combination of an AES cipher and a CBC cipher mode for encrypted filesystems, which allows local users to obtain sensitive information via a watermark attack.
{ "ubuntu_priority": "medium", "availability": "No subscription required", "binaries": [ { "binary_name": "encfs", "binary_version": "1.7.4-2.4ubuntu2" } ] }