SB2018031919 - Multiple vulnerabilities in www.truecrypt truecrypt



SB2018031919 - Multiple vulnerabilities in www.truecrypt truecrypt

Published: March 19, 2018 Updated: August 8, 2020

Security Bulletin ID SB2018031919
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Information disclosure (CVE-ID: CVE-2014-2884)

The vulnerability allows a local authenticated user to gain access to sensitive information.

The ProcessVolumeDeviceControlIrp function in Ntdriver.c in TrueCrypt 7.1a allows local users to bypass access restrictions and obtain sensitive information about arbitrary files via a (1) TC_IOCTL_OPEN_TEST or (2) TC_IOCTL_GET_SYSTEM_DRIVE_CONFIG IOCTL call.


2) Integer overflow (CVE-ID: CVE-2014-2885)

The vulnerability allows a local authenticated user to #BASIC_IMPACT#.

Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving a crafted item->OriginalLength value in the MainThreadProc function in EncryptedIoQueue.c or (2) cause a denial of service (memory consumption) via vectors involving large StartingOffset and Length values in the ProcessVolumeDeviceControlIrp function in Ntdriver.c.


Remediation

Install update from vendor's website.