PT-2006-3162 · Truecrypt · Truecrypt
Published
2006-05-04
·
Updated
2017-07-20
·
CVE-2006-2183
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Truecrypt version 4.1
Description
The issue allows local users to execute arbitrary commands and gain privileges via a modified
PATH environment variable that references a malicious mount command. This occurs when Truecrypt is running suid root on Linux.Recommendations
For Truecrypt version 4.1, consider restricting the use of the suid root functionality on Linux systems until a fix is available. As a temporary workaround, ensure that the
PATH environment variable is properly set and validated to prevent malicious modifications.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Truecrypt