summaryrefslogtreecommitdiffstats
path: root/ignored/CVE-2004-2135
blob: eabd4119dfc15da4c3c8cc4adbdee8ed9cfc12c2 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
Candidate: CVE-2004-2135
References: 
 http://marc.theaimsgroup.com/?l=linux-kernel&m=107719798631935&w=2
 http://mareichelt.de/pub/notmine/diskenc.pdf
 http://www.securiteam.com/exploits/5UP0P1PFPM.html
 http://www.securityfocus.com/bid/13775
Description: 
 cryptoloop on Linux kernel 2.6.x, when used on certain file systems with a
 block size 1024 or greater, has certain "IV computation" weaknesses that
 allow watermarked files to be detected without decryption.
Notes: 
 jmm> IIRC there was some serious flaming about the different disk encryption systems,
 jmm> I'm not sure whether this has been addressed or how real it is
 jmm> Plus, cryptoloop is marked DEPRECATED for a long time IIRC
 jmm> It's not included in stock 2.4 kernels, but only available in kernel-patch-cryptoloop,
 jmm> which is only part of sid and hasn't been shipped with neither Woody nor Sarge, so
 jmm> I'm marking all these N/A
Bugs: 
upstream: 
linux-2.6:
2.6.8-sarge-security: ignored (2.6.8-16sarge5)
2.4.27-sarge-security: N/A
2.6.18-etch-security: ignored

© 2014-2024 Faster IT GmbH | imprint | privacy policy