[kernel-sec-discuss] r1636 - active ignored

Michael Gilbert gilbert-guest at alioth.debian.org
Sat Dec 5 03:59:06 UTC 2009


Author: gilbert-guest
Date: 2009-12-05 03:59:06 +0000 (Sat, 05 Dec 2009)
New Revision: 1636

Removed:
   ignored/CVE-2004-2135
Modified:
   active/CVE-2004-2135
Log:
merge crytoloop issue (i hadn't known those were in 'ignored' until just now)

Modified: active/CVE-2004-2135
===================================================================
--- active/CVE-2004-2135	2009-12-05 03:59:03 UTC (rev 1635)
+++ active/CVE-2004-2135	2009-12-05 03:59:06 UTC (rev 1636)
@@ -8,12 +8,19 @@
  http://mareichelt.de/pub/notmine/diskenc.pdf
  http://mareichelt.de/pub/texts.cryptoloop.php?alt_styles=2
 Notes:
+ jmm> IIRC there was some serious flaming about the different disk encryption systems,
+ jmm> I'm not sure whether this has been addressed or how real it is
+ jmm> Plus, cryptoloop is marked DEPRECATED for a long time IIRC
+ jmm> It's not included in stock 2.4 kernels, but only available in kernel-patch-cryptoloop,
+ jmm> which is only part of sid and hasn't been shipped with neither Woody nor Sarge, so
+ jmm> I'm marking all these N/A 
  - i am 99% sure that these issues still affect the latest kernels
  - debian-installer only supports loop-aes and dm-crypt (i believe),
    which are known to be not affected by these issues, so most users
    are not affected
  - perhaps a solution would be to disable cryptoloop?
- - i have started an lkml thread: http://lkml.org/lkml/2009/12/2/232
+ - i have started an lkml thread: http://lkml.org/lkml/2009/12/2/232, but it appears
+   that there is no longer any interest in the problems...
 Bugs:
 upstream:
 linux-2.6:

Deleted: ignored/CVE-2004-2135
===================================================================
--- ignored/CVE-2004-2135	2009-12-05 03:59:03 UTC (rev 1635)
+++ ignored/CVE-2004-2135	2009-12-05 03:59:06 UTC (rev 1636)
@@ -1,24 +0,0 @@
-Candidate: CVE-2004-2135
-References: 
- http://marc.theaimsgroup.com/?l=linux-kernel&m=107719798631935&w=2
- http://mareichelt.de/pub/notmine/diskenc.pdf
- http://www.securiteam.com/exploits/5UP0P1PFPM.html
- http://www.securityfocus.com/bid/13775
-Description: 
- cryptoloop on Linux kernel 2.6.x, when used on certain file systems with a
- block size 1024 or greater, has certain "IV computation" weaknesses that
- allow watermarked files to be detected without decryption.
-Notes: 
- jmm> IIRC there was some serious flaming about the different disk encryption systems,
- jmm> I'm not sure whether this has been addressed or how real it is
- jmm> Plus, cryptoloop is marked DEPRECATED for a long time IIRC
- jmm> It's not included in stock 2.4 kernels, but only available in kernel-patch-cryptoloop,
- jmm> which is only part of sid and hasn't been shipped with neither Woody nor Sarge, so
- jmm> I'm marking all these N/A
-Bugs: 
-upstream: 
-linux-2.6:
-2.6.8-sarge-security: ignored (2.6.8-16sarge5)
-2.4.27-sarge-security: N/A
-2.6.18-etch-security: ignored
-




More information about the kernel-sec-discuss mailing list