TrueCrypt 4.3, when installed setuid root, allows local users to cause a denial of service (filesystem unavailability) or gain privileges by mounting a crafted TrueCrypt volume, as demonstrated using (1) /usr/bin or (2) another users home directory, a different issue than CVE-2007-1589.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Truecrypt | Truecrypt_foundation | 3.0 (including) | 3.0 (including) |
Truecrypt | Truecrypt_foundation | 4.0 (including) | 4.0 (including) |
Truecrypt | Truecrypt_foundation | 4.1 (including) | 4.1 (including) |
Truecrypt | Truecrypt_foundation | 4.2 (including) | 4.2 (including) |
Truecrypt | Truecrypt_foundation | 4.3 (including) | 4.3 (including) |