>> TrueCrypt "PATH" Environment Handling Local Privilege Escalation Vulnerability
Title : TrueCrypt "PATH" Environment Handling Local Privilege Escalation Vulnerability VUPEN ID : VUPEN/ADV-2006-1591 CVE ID : CVE-2006-2183
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-05-01
Technical Description
A vulnerability has been identified in TrueCrypt, which could be exploited by local attackers to obtain elevated privileges. This flaw is due to an input validation error when processing path environments before calling the "execvp()" function, which could be exploited by malicious users to execute arbitrary commands with root privileges.