PT-2008-5233 · Truecrypt · Truecrypt

Jonathan Brossard

·

Publicado

2008-09-03

·

Atualizado

2018-10-11

·

CVE-2008-3899

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions TrueCrypt version 5.0
Description The issue allows local users to obtain sensitive information by reading physical memory locations. This is due to the storage of pre-boot authentication passwords in the BIOS Keyboard buffer without properly clearing the buffer before and after use.
Recommendations For TrueCrypt version 5.0, consider disabling the pre-boot authentication feature until a proper fix is implemented to clear the BIOS Keyboard buffer after use.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3899

Produtos afetados

Truecrypt