Age | Commit message (Collapse) | Author | Files | Lines | |
---|---|---|---|---|---|
10 days | Translations: Update translations of newly added fields | Mounir IDRASSI | 1 | -3/+3 | |
10 days | Linux/FreeBSD: Prevent mounting volumes on system directories and PATH ↵ | Mounir IDRASSI | 1 | -0/+3 | |
(CVE-2025-23021, reported by SivertPL @__tfr) Added security checks to prevent mounting VeraCrypt volumes on system directories (like /usr/bin) or directories in the user's PATH, which could theoretically allow execution of malicious binaries instead of legitimate system binaries. Key changes: - Block mounting on protected system directories (/usr, /bin, /lib, etc.) This restriction cannot be overridden - Block mounting on directories present in user's PATH environment variable This can be overridden with --allow-insecure-mount flag - Add visual warnings (red border, "[INSECURE MODE]") when mounting on PATH directories is allowed - Handle symlinks properly when checking paths - Add new error messages for blocked mount points To override PATH-based restrictions only (system directories remain protected): veracrypt --allow-insecure-mount [options] volume mountpoint Security Impact: Low to Medium The attack requires either: - User explicitly choosing a system directory as mount point instead of using VeraCrypt's default mount points - Or attacker having both filesystem access to modify favorites configuration AND knowledge of the volume password Default mount points are not affected by this vulnerability. Security: CVE-2025-23021 | |||||
10 days | Increment version to 1.26.18. Update copyright date. Update Release Notes. ↵ | Mounir IDRASSI | 1 | -1/+1 | |
Update Windows drivers. | |||||
2024-11-20 | Windows driver: use correct WDM type. Increment version to 1.26.17 | Mounir IDRASSI | 1 | -1/+1 | |
2024-11-18 | Increment version to 1.26.16. Update Release Notes. Update signed Windows ↵ | Mounir IDRASSI | 1 | -1/+1 | |
drivers. | |||||
2024-09-01 | Windows: Fix MSI not installing all new documentation file. Remove old files ↵ | Mounir IDRASSI | 1 | -1/+1 | |
left from old versions. Increment version to 1.26.15. | |||||
2024-08-25 | Increment version to 1.26.14. Set release date to August 25th. | Mounir IDRASSI | 1 | -1/+1 | |
2024-08-13 | Update Finnish translation and few xml errors (#1400) | Jertzukka | 1 | -1/+1 | |
2024-08-11 | Fix another typo of "CPLC" is language files including English one. | Mounir IDRASSI | 1 | -1/+1 | |
2024-08-05 | Undeclared identifier for IDR_LANG_NB fixed (#1388) | Marius Kjærstad | 1 | -1/+1 | |
2024-08-04 | Translations: Fix typo in Norwegian translation | Mounir IDRASSI | 1 | -1/+1 | |
2024-08-03 | Add missing translated entries to Norwegian language file. (#1386) | chatgptdev | 1 | -0/+3 | |
Translation was done using gpt-4o (multi-shot) and validated with Claude Sonnet 3.5 and Google Gemini 1.5 Pro Experimental 0801 Co-authored-by: Mounir IDRASSI <mounir.idrassi@idrix.fr> | |||||
2024-08-03 | Add Norwegian Bokmål translation (#1382) | Marius Kjærstad | 1 | -0/+1684 | |
* Add Norwegian Bokmål translation * Fix Norwegian Bokmål translation |