Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-2885

Опубликовано: 19 мар. 2018
Источник: nvd
CVSS3: 7.1
CVSS2: 3.6
EPSS Низкий

Описание

Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving a crafted item->OriginalLength value in the MainThreadProc function in EncryptedIoQueue.c or (2) cause a denial of service (memory consumption) via vectors involving large StartingOffset and Length values in the ProcessVolumeDeviceControlIrp function in Ntdriver.c.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:truecrypt_project:truecrypt:7.1:a:*:*:*:*:*:*

EPSS

Процентиль: 12%
0.0004
Низкий

7.1 High

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 7.1
debian
почти 8 лет назад

Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) ...

CVSS3: 7.1
github
больше 3 лет назад

Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving a crafted item->OriginalLength value in the MainThreadProc function in EncryptedIoQueue.c or (2) cause a denial of service (memory consumption) via vectors involving large StartingOffset and Length values in the ProcessVolumeDeviceControlIrp function in Ntdriver.c.

EPSS

Процентиль: 12%
0.0004
Низкий

7.1 High

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-190