The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and adding 8 to "blockMACRandBytes".
{ "availability": "No subscription required", "binaries": [ { "binary_version": "1.8.1-3", "binary_name": "encfs" }, { "binary_version": "1.8.1-3", "binary_name": "encfs-dbgsym" } ], "ubuntu_priority": "high" }