First published: Wed Mar 21 2007(Updated: )
TrueCrypt before 4.3, when set-euid mode is used on Linux, allows local users to cause a denial of service (filesystem unavailability) by dismounting a volume mounted by a different user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linux kernel | ||
TrueCrypt | =4.0 | |
TrueCrypt | =4.1 | |
TrueCrypt | =4.2 | |
TrueCrypt | =4.2a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1589 is assessed as a moderate severity vulnerability because it allows local users to disrupt filesystem access.
To mitigate CVE-2007-1589, upgrade TrueCrypt to version 4.3 or a later version that addresses this issue.
CVE-2007-1589 affects local users on systems running TrueCrypt versions 4.0, 4.1, 4.2, or 4.2a that utilize set-euid mode.
CVE-2007-1589 can lead to denial of service, resulting in filesystem unavailability for volumes mounted by other users.
CVE-2007-1589 is a local vulnerability, as it requires access to the machine where TrueCrypt is running.