FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

tarsnap -- cryptographic nonce reuse

Affected packages
1.0.22 <= tarsnap <= 1.0.27


VuXML ID 2c2d4e83-2370-11e0-a91b-00e0815b8da8
Discovery 2011-01-18
Entry 2011-01-19

Colin Percival reports:

In versions 1.0.22 through 1.0.27 of Tarsnap, the CTR nonce value is not incremented after each chunk is encrypted. (The CTR counter is correctly incremented after each 16 bytes of data was processed, but this counter is reset to zero for each new chunk.)

Note that since the Tarsnap client-server protocol is encrypted, being able to intercept Tarsnap client-server traffic does not provide an attacker with access to the data.