CVE-2007-1738: Medium severity Truecrypt Foundation Truecrypt vulnerability
TrueCrypt 4.3, when installed setuid root, allows local users to cause a denial of service (filesystem unavailability) or gain privileges by mounting a crafted TrueCrypt volume, as demonstrated using (1) /usr/bin or (2) another user's home directory, a different issue than CVE-2007-1589.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1738?
CVE-2007-1738 has a moderate severity level, potentially leading to denial of service or privilege escalation.
How do I fix CVE-2007-1738?
To fix CVE-2007-1738, ensure that TrueCrypt is not setuid root and consider updating to a newer version.
Who is affected by CVE-2007-1738?
Users of TrueCrypt versions 3.0 through 4.3 that have it installed with setuid root permissions are affected by CVE-2007-1738.
What types of attacks are possible with CVE-2007-1738?
CVE-2007-1738 could allow local users to mount a crafted TrueCrypt volume, leading to denial of service or privilege escalation.
Is CVE-2007-1738 resolved in newer TrueCrypt versions?
CVE-2007-1738 is resolved in newer TrueCrypt versions following 4.3, so upgrading is recommended to mitigate the vulnerability.