summaryrefslogtreecommitdiffstats
path: root/retired/CVE-2004-2135
diff options
context:
space:
mode:
authorRaphael Geissert <geissert@debian.org>2009-12-19 21:03:31 +0000
committerRaphael Geissert <geissert@debian.org>2009-12-19 21:03:31 +0000
commit33f69ec333724a9646d989dbba381ac59bbcfb8c (patch)
tree6438836b1db3dee8e76528e4b248ad84dc53d6d8 /retired/CVE-2004-2135
parent13a98d63ed3956080f68af25558d1034efb887e2 (diff)
retire cyptoloop issue
git-svn-id: svn+ssh://svn.debian.org/svn/kernel-sec@1660 e094ebfe-e918-0410-adfb-c712417f3574
Diffstat (limited to 'retired/CVE-2004-2135')
-rw-r--r--retired/CVE-2004-213529
1 files changed, 29 insertions, 0 deletions
diff --git a/retired/CVE-2004-2135 b/retired/CVE-2004-2135
new file mode 100644
index 00000000..dac9d7a6
--- /dev/null
+++ b/retired/CVE-2004-2135
@@ -0,0 +1,29 @@
+Candidate: CVE-2004-2135
+Description:
+ cryptoloop on Linux kernel 2.6.x, when used on certain file systems with a block
+ size 1024 or greater, has certain "IV computation" weaknesses that allow watermarked
+ files to be detected without decryption.
+References:
+ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2135
+ http://mareichelt.de/pub/notmine/diskenc.pdf
+ http://mareichelt.de/pub/texts.cryptoloop.php?alt_styles=2
+Notes:
+ jmm> IIRC there was some serious flaming about the different disk encryption systems,
+ jmm> I'm not sure whether this has been addressed or how real it is
+ jmm> Plus, cryptoloop is marked DEPRECATED for a long time IIRC
+ jmm> It's not included in stock 2.4 kernels, but only available in kernel-patch-cryptoloop,
+ jmm> which is only part of sid and hasn't been shipped with neither Woody nor Sarge, so
+ jmm> I'm marking all these N/A
+ - i am 99% sure that these issues still affect the latest kernels
+ - debian-installer only supports loop-aes and dm-crypt (i believe),
+ which are known to be not affected by these issues, so most users
+ are not affected
+ - i have started an lkml thread: http://lkml.org/lkml/2009/12/2/232, but it appears
+ that there is no longer any interest in the problems...
+ jmm> Disabled in 2.6.32-2
+Bugs:
+upstream:
+linux-2.6: released (2.6.32-2)
+2.6.18-etch-security: N/A "introduces significant change in funtionality; minor issue"
+2.6.24-etch-security: N/A "introduces significant change in funtionality; minor issue"
+2.6.26-lenny-security: N/A "introduces significant change in funtionality; minor issue"

© 2014-2024 Faster IT GmbH | imprint | privacy policy