MGASA-2021-0088 - Updated veracrypt package fixes a security vulnerability

Publication date: 19 Feb 2021
URL: https://advisories.mageia.org/MGASA-2021-0088.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-1010208

IDRIX, Truecrypt Veracrypt, Truecrypt Prior to 1.23-Hotfix-1 (Veracrypt), all
versions (Truecrypt) is affected by a Buffer Overflow that can lead to 
information disclosure of kernel stack through a locally executed code with
IOCTL request to driver (CVE-2019-1010208).

References:
- https://bugs.mageia.org/show_bug.cgi?id=28078
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010208

SRPMS:
- 7/core/veracrypt-1.23-1.2.mga7

Mageia 2021-0088: veracrypt security update

IDRIX, Truecrypt Veracrypt, Truecrypt Prior to 1.23-Hotfix-1 (Veracrypt), all versions (Truecrypt) is affected by a Buffer Overflow that can lead to information disclosure of kern...

Summary

IDRIX, Truecrypt Veracrypt, Truecrypt Prior to 1.23-Hotfix-1 (Veracrypt), all versions (Truecrypt) is affected by a Buffer Overflow that can lead to information disclosure of kernel stack through a locally executed code with IOCTL request to driver (CVE-2019-1010208).

References

- https://bugs.mageia.org/show_bug.cgi?id=28078

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010208

Resolution

MGASA-2021-0088 - Updated veracrypt package fixes a security vulnerability

SRPMS

- 7/core/veracrypt-1.23-1.2.mga7

Severity
Publication date: 19 Feb 2021
URL: https://advisories.mageia.org/MGASA-2021-0088.html
Type: security
CVE: CVE-2019-1010208

Related News