Bug 246760 - (CVE-2007-3528) CVE-2007-3528 dar Blowfish-CBC weakness
CVE-2007-3528 dar Blowfish-CBC weakness
Product: Fedora
Classification: Fedora
Component: dar (Show other bugs)
All Linux
low Severity low
: ---
: ---
Assigned To: Chris Petersen
Fedora Extras Quality Assurance
: Security
Depends On:
  Show dependency treegraph
Reported: 2007-07-04 13:15 EDT by Ville Skyttä
Modified: 2007-11-30 17:12 EST (History)
1 user (show)

See Also:
Fixed In Version: 2.3.4-1.fc7
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2007-07-05 15:24:45 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Ville Skyttä 2007-07-04 13:15:30 EDT

"The blowfish mode in DAR before 2.3.4 uses weak Blowfish-CBC cryptography by
(1) discarding random bits by the blowfish::make_ivec function in
libdar/crypto.cpp that results in predictable and repeating IV values, and (2)
direct use of a password for keying, which makes it easier for context-dependent
attackers to decrypt files."

2.3.4 is in CVS for F-7+, FC-6 appears untreated at the moment.

Please mark the F-7 update as a security one in the updates system and add the
CVE reference to it (I have no permissions to do that).
Comment 1 Chris Petersen 2007-07-04 13:41:19 EDT
Updated in bodhi, should roll out asap.  Also updated FC-6 and Epel.  This bug
should auto-close when F-7 rolls out.
Comment 2 Fedora Update System 2007-07-05 15:24:42 EDT
dar-2.3.4-1.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.