PT-2006-3162 · Truecrypt · Truecrypt

Published

2006-05-04

·

Updated

2017-07-20

·

CVE-2006-2183

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Truecrypt version 4.1
Description The issue allows local users to execute arbitrary commands and gain privileges via a modified PATH environment variable that references a malicious mount command. This occurs when Truecrypt is running suid root on Linux.
Recommendations For Truecrypt version 4.1, consider restricting the use of the suid root functionality on Linux systems until a fix is available. As a temporary workaround, ensure that the PATH environment variable is properly set and validated to prevent malicious modifications.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2183

Affected Products

Truecrypt