PT-2007-3104 · Truecrypt · Truecrypt

Publicado

2007-03-28

·

Atualizado

2018-10-16

·

CVE-2007-1738

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: TrueCrypt version 4.3
Description: The issue allows local users to cause a denial of service or gain privileges by mounting a crafted TrueCrypt volume. This can be demonstrated by mounting the volume in sensitive locations such as /usr/bin or another user's home directory.
Recommendations: For TrueCrypt version 4.3, consider removing the setuid root installation to prevent exploitation until a patch is available. As a temporary workaround, restrict access to sensitive directories to minimize the risk of privilege escalation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1738

Produtos afetados

Truecrypt