Bug 246760 (CVE-2007-3528) - CVE-2007-3528 dar Blowfish-CBC weakness
Summary: CVE-2007-3528 dar Blowfish-CBC weakness
Alias: CVE-2007-3528
Product: Fedora
Classification: Fedora
Component: dar
Version: 7
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Chris Petersen
QA Contact: Fedora Extras Quality Assurance
Keywords: Security
Depends On:
TreeView+ depends on / blocked
Reported: 2007-07-04 17:15 UTC by Ville Skyttä
Modified: 2007-11-30 22:12 UTC (History)
1 user (show)

Clone Of:
Last Closed: 2007-07-05 19:24:45 UTC

Attachments (Terms of Use)

Description Ville Skyttä 2007-07-04 17:15:30 UTC

"The blowfish mode in DAR before 2.3.4 uses weak Blowfish-CBC cryptography by
(1) discarding random bits by the blowfish::make_ivec function in
libdar/crypto.cpp that results in predictable and repeating IV values, and (2)
direct use of a password for keying, which makes it easier for context-dependent
attackers to decrypt files."

2.3.4 is in CVS for F-7+, FC-6 appears untreated at the moment.

Please mark the F-7 update as a security one in the updates system and add the
CVE reference to it (I have no permissions to do that).

Comment 1 Chris Petersen 2007-07-04 17:41:19 UTC
Updated in bodhi, should roll out asap.  Also updated FC-6 and Epel.  This bug
should auto-close when F-7 rolls out.

Comment 2 Fedora Update System 2007-07-05 19:24:42 UTC
dar-2.3.4-1.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.