about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , TrueCrypt <= 4.3 Local Privilege Escalation Exploit (CVE-2007-1738)



2007-04-04 TrueCrypt <= 4.3 Local Privilege Escalation Exploit (CVE-2007-1738)
Rated as : Critical

# $Id: raptor_truecrypt,v 1.1.1.1 2007/04/04 11:31:56 raptor Exp $
#
# raptor_truecrypt - setuid truecrypt privilege escalation
# Copyright (c) 2007 Marco Ivaldi <raptor@0xdeadbeef.info>
#
# TrueCrypt 4.3, when installed setuid root, allows local users to cause a

# denial of service (filesystem unavailability) or gain privileges by
mounting 
# a crafted TrueCrypt volume, as demonstrated using (1) /usr/bin or (2)
another
# user's home directory, a different issue than CVE-2007-1589
(CVE-2007-1738).
#
# WARNING: THIS IS A PROOF OF CONCEPT EXPLOIT TAKING ADVANTAGE OF NPTL
THREAD
# LOCAL STORAGE DYNAMIC LINKING MODEL, DO NOT USE IT IF YOU DON'T KNOW HOW
IT
# WORKS! YEAH, IT *DOES* REQUIRE SOME TWEAKINGS TO EXPLOIT NON-TLS
PLATFORMS!
#
# Other possible attack vectors:
/etc/cron.{d,hourly,daily,weekly,monthly}, at 
# (/var/spool/atjobs/), xinetd (/etc/xinetd.d), /etc/logrotate.d, and
more...

http://www.0xdeadbeef.info/exploits/raptor_truecrypt.tgz
http://www.milw0rm.com/sploits/04042007-raptor_truecrypt.tgz
securitydot.net - 2007-04-04

Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 17:13:18 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
news for c Www.Sixy g php html e security e www. pinkw ip+board+2 ip+board+2 global ann www.blackg www.0733.l LOCAL Sex vido.c Www.sexypi www.mqdm.n mcnasvc Wapetrick php-nuke 2 adm Xxxnoir Netgear DG Two hot gr mambo Remo horse sex camelclips 96.0.204.1 newseum faq sexs video File Incl 200+%252Fc Desnudas Asp shop a Www.Arapek www.sootoo www.sexxx Phon on se www.pinkwo Www.School maxcpm.inf /search/ex ww.89com CMS is Fre nameeta music vide www.xayf.c ip+board+2 Www.malika ip+board+2 Crack+Data Www.Arapek