blob: b058dc3ae6dbcd1c1aa98d40fb7115083aa7c57b (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
|
Candidate: CVE-2004-2136
References:
http://marc.theaimsgroup.com/?l=linux-kernel&m=107719798631935&w=2
http://mareichelt.de/pub/notmine/diskenc.pdf
http://www.securiteam.com/exploits/5UP0P1PFPM.html
Description:
dm-crypt on Linux kernel 2.6.x, when used on certain file systems with a
block size 1024 or greater, has certain "IV computation" weaknesses that
allow watermarked files to be detected without decryption.
Notes:
jmm> IIRC there was some serious flaming about the different disk encryption systems,
jmm> I'm not sure whether this has been addressed or how real it is
jmm> 2.4 doesn't have dm-crypt, though
Bugs:
upstream:
linux-2.6:
2.6.8-sarge-security: ignored (2.6.8-16sarge5)
2.4.27-sarge-security: N/A
2.6.18-etch-security: ignored
|