<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="7f3f14b55ba6b890b38c801f8c66c6b3"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="3641">
  <id>dbg111-encfs</id>
  <title>encfs: security update</title>
  <release>openSUSE 11.1 DEBUGINFO</release>
  <issued date="1291643771"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=637286" id="637286" title="bug number 637286" type="bugzilla"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3073" id="CVE-2010-3073" title="CVE-2010-3073" type="cve"/>
    <reference href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3074" id="CVE-2010-3074" title="CVE-2010-3074" type="cve"/>
  </references>
  <description>This update of encfs fixes:
- CVE-2010-3073: CVSS v2 Base Score: 1.9
  (AV:L/AC:M/Au:N/C:P/I:N/A:N): Cryptographic Issues
  (CWE-310): encfs Only 32 bit of file IV used
- CVE-2010-3074: CVSS v2 Base Score: 1.9
  (AV:L/AC:M/Au:N/C:P/I:N/A:N): Cryptographic Issues
  (CWE-310): encfs Watermarking attack

The patch for CVE-2010-3075 (Last block with single byte is
insecure) was not applied because upstream disabled it by
default, expect for expert mode.
</description>
  <pkglist>
    <collection>
        <package name="encfs-debuginfo" arch="i586" version="1.5.0" release="1.17.1">
          <filename>encfs-debuginfo-1.5.0-1.17.1.i586.rpm</filename>
        </package>
        <package name="encfs-debuginfo" arch="ppc" version="1.5.0" release="1.17.1">
          <filename>encfs-debuginfo-1.5.0-1.17.1.ppc.rpm</filename>
        </package>
        <package name="encfs-debuginfo" arch="x86_64" version="1.5.0" release="1.17.1">
          <filename>encfs-debuginfo-1.5.0-1.17.1.x86_64.rpm</filename>
        </package>
        <package name="encfs-debugsource" arch="i586" version="1.5.0" release="1.17.1">
          <filename>encfs-debugsource-1.5.0-1.17.1.i586.rpm</filename>
        </package>
        <package name="encfs-debugsource" arch="ppc" version="1.5.0" release="1.17.1">
          <filename>encfs-debugsource-1.5.0-1.17.1.ppc.rpm</filename>
        </package>
        <package name="encfs-debugsource" arch="x86_64" version="1.5.0" release="1.17.1">
          <filename>encfs-debugsource-1.5.0-1.17.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
