The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and adding 8 to "blockMACRandBytes".
{ "binaries": [ { "binary_name": "encfs", "binary_version": "1.8.1-3" }, { "binary_name": "encfs-dbgsym", "binary_version": "1.8.1-3" } ], "availability": "No subscription required" }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-3462.json"