First published: Wed Mar 28 2007(Updated: )
TrueCrypt 4.3, when installed setuid root, allows local users to cause a denial of service (filesystem unavailability) or gain privileges by mounting a crafted TrueCrypt volume, as demonstrated using (1) /usr/bin or (2) another user's home directory, a different issue than CVE-2007-1589.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TrueCrypt | =4.0 | |
TrueCrypt | =4.3 | |
TrueCrypt | =3.0 | |
TrueCrypt | =4.2 | |
TrueCrypt | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1738 has a moderate severity level, potentially leading to denial of service or privilege escalation.
To fix CVE-2007-1738, ensure that TrueCrypt is not setuid root and consider updating to a newer version.
Users of TrueCrypt versions 3.0 through 4.3 that have it installed with setuid root permissions are affected by CVE-2007-1738.
CVE-2007-1738 could allow local users to mount a crafted TrueCrypt volume, leading to denial of service or privilege escalation.
CVE-2007-1738 is resolved in newer TrueCrypt versions following 4.3, so upgrading is recommended to mitigate the vulnerability.