CVE-2014-2885
19.03.2018, 21:29
Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving a crafted item->OriginalLength value in the MainThreadProc function in EncryptedIoQueue.c or (2) cause a denial of service (memory consumption) via vectors involving large StartingOffset and Length values in the ProcessVolumeDeviceControlIrp function in Ntdriver.c.Enginsight
Vendor | Product | Version |
---|---|---|
truecrypt_project | truecrypt | 7.1:a |
𝑥
= Vulnerable software versions
References