CVE-2019-1010208

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-1010208
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-1010208.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-1010208
Related
Published
2019-07-23T14:15:13Z
Modified
2025-10-21T04:41:56.235622Z
Severity
  • 3.3 (Low) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

IDRIX, Truecrypt Veracrypt, Truecrypt Prior to 1.23-Hotfix-1 (Veracrypt), all versions (Truecrypt) is affected by: Buffer Overflow. The impact is: Minor information disclosure of kernel stack. The component is: Veracrypt NT Driver (veracrypt.sys). The attack vector is: Locally executed code, IOCTL request to driver. The fixed version is: 1.23-Hotfix-1.

References

Affected packages

Git / github.com/veracrypt/veracrypt

Affected ranges

Type
GIT
Repo
https://github.com/veracrypt/veracrypt
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

VeraCrypt_1.*

VeraCrypt_1.0a
VeraCrypt_1.0b
VeraCrypt_1.0c
VeraCrypt_1.0d
VeraCrypt_1.0e
VeraCrypt_1.0f
VeraCrypt_1.0f-1
VeraCrypt_1.0f-2
VeraCrypt_1.0f-BETA
VeraCrypt_1.0f-BETA2
VeraCrypt_1.0f-BETA3
VeraCrypt_1.12
VeraCrypt_1.13
VeraCrypt_1.14
VeraCrypt_1.15
VeraCrypt_1.16
VeraCrypt_1.17
VeraCrypt_1.18
VeraCrypt_1.18_PreRelease
VeraCrypt_1.18a
VeraCrypt_1.19
VeraCrypt_1.20
VeraCrypt_1.21
VeraCrypt_1.22
VeraCrypt_1.23

VeraCrypt_Linux_1.*

VeraCrypt_Linux_1.0d
VeraCrypt_Linux_1.0e
VeraCrypt_Linux_1.0f-BETA

VeraCrypt_MacOSX_1.*

VeraCrypt_MacOSX_1.0d
VeraCrypt_MacOSX_1.0e
VeraCrypt_MacOSX_1.0f-BETA

Database specific

vanir_signatures

[
    {
        "signature_type": "Function",
        "digest": {
            "function_hash": "99260500089225585535400202953315261036",
            "length": 23457.0
        },
        "target": {
            "file": "src/Driver/Ntdriver.c",
            "function": "ProcessMainDeviceControlIrp"
        },
        "source": "https://github.com/veracrypt/veracrypt/commit/f30f9339c9a0b9bbcc6f5ad38804af39db1f479e",
        "id": "CVE-2019-1010208-5ac8f030",
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "12251207091778942331758691273137997068",
                "228403932235185941928329809776944603517",
                "207699067412301927530895601827383600649",
                "156982102621042307054045683717540140021",
                "166434412347977751743618310013300448676",
                "16927126674612411906536661442620066041",
                "220638490978864453749445881527584555100",
                "168072697142537181309356397822787292295",
                "317988438505038381541748079228259006430",
                "340195054385175002238653384065562555476",
                "41905034580316349525792025615588139376",
                "63592138887244521358261557549902901280",
                "16385092768403608804112045502830058103",
                "154450026428575538184751231522328749214",
                "58866370893220054509888526794745057433",
                "248990029171671349058148987249788613207",
                "295421033534230860536403471679879564469",
                "85930207431484817954531047385704321584",
                "103065638869166797963703561449157684262",
                "145977198325931997074915358775757301426",
                "95689836982762025101200788325028862809",
                "285159872877492032806417467412076890522",
                "190035593735886369543144058085254158142",
                "216314928064801080804870107707279297188",
                "124018408423230380348750215568465770331",
                "66149616286213583688671257386286223902",
                "128103108340881671052682829582529915893",
                "269480055231776471187305682988433327942",
                "134935012340010213857951085429519089249",
                "176967662115058230916672518055265117726",
                "316557320386490258170658345737356530710",
                "75407180318704451699303769443305508093",
                "167335110034189503231198577217191264592",
                "327388182601790397550097086971690825233",
                "330548656852901841940771491689015448853",
                "49890293247161868526903577171161934461",
                "60350789467647832487822457434471553323",
                "89340101075518717543561950512707686770",
                "338740138996802110096387178036929212594",
                "34391523128672584739411886739709059568",
                "39396940989251570747904511005532187556",
                "320859386759073570304533866794430884210",
                "264981601008212062306571594757974894797",
                "16148004680451891155607336704809833826",
                "197222094082338846834530659899752715421",
                "32563556060328678061854253025922696721",
                "311321260924280009769457962272188931476",
                "316119318636241063314219662104157774936",
                "146578716263682552271086113831492594212",
                "236732265184660035366467935863000898408",
                "123186417481274532406501401369472818629",
                "121731733516853163756628308200565320452",
                "339452009732192817739419477977655061825",
                "303967730498139037239047973646668176254",
                "123945678052741425447485001585198213492",
                "321174699455353661484887177908397211604",
                "51846879331338098189501490298779493154",
                "304565358498203375837974403514222749331",
                "272719061591551695996980419599736791917",
                "197485174169960571957745106087008119029"
            ]
        },
        "target": {
            "file": "src/Driver/Ntdriver.c"
        },
        "source": "https://github.com/veracrypt/veracrypt/commit/f30f9339c9a0b9bbcc6f5ad38804af39db1f479e",
        "id": "CVE-2019-1010208-98d3b6e6",
        "deprecated": false,
        "signature_version": "v1"
    }
]