CVE-2014-3462: Encfs Project Encfs
High severity, CVSS 7.5. EPSS: 3.1% chance of exploitation in the next 30 days.
The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and adding 8 to "blockMACRandBytes".
Affected products
- Encfs Project Encfs: before 1.7.5 (fixed in 1.7.5)
- Opensuse Leap: version 42.1 only; version 42.2 only
- Opensuse Opensuse: version 13.2 only
Published 2017-08-07. Last modified 2026-06-17.