CVE-2006-2183: High severity Truecrypt Foundation Truecrypt vulnerability
Published May 4, 2006
·Updated
Untrusted search path vulnerability in Truecrypt 4.1, when running suid root on Linux, allows local users to execute arbitrary commands and gain privileges via a modified PATH environment variable that references a malicious mount command.
Affected Software
1 affected component
Truecrypt Foundation Truecrypt=4.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
May 4, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2183?
CVE-2006-2183 is classified as a critical vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2006-2183?
To mitigate CVE-2006-2183, users should upgrade to a newer version of TrueCrypt that does not have this vulnerability.
3
Who is affected by CVE-2006-2183?
Local users running TrueCrypt 4.1 with SUID root on Linux systems are affected by CVE-2006-2183.
4
What type of attack does CVE-2006-2183 facilitate?
CVE-2006-2183 facilitates privilege escalation by allowing local users to execute arbitrary commands.
5
What software is associated with CVE-2006-2183?
CVE-2006-2183 is associated with TrueCrypt version 4.1.