Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Debian DLA-3054-1 Critical: Sleuth Kit Denial Of Service Advisory

debian lts
Calendar Grey June 20, 2022
Dist Debian Esm H88
Addressing multiple security weaknesses in the Sleuth Kit repository for Debian LTS, including essential updates and resolutions
Brief introduction CVE-2017-13755

Summary

Opening a crafted ISO 9660 image triggers an out-of-bounds
read in iso9660_proc_dir() in tsk/fs/iso9660_dent.c in libtskfs.a, as
demonstrated by fls.

CVE-2017-13756

Opening a crafted disk image triggers infinite recursion in
dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as demonstrated by
mmls.

CVE-2017-13760

fls hangs on a corrupt exfat image in tsk_img_read() in
tsk/img/img_io.c in libtskimg.a.

CVE-2018-19497

In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in
tsk/fs/hfs.c does not properly determine when a key length is too large,
which allows attackers to cause a denial of service (SEGV on unknown
address with READ memory access in a tsk_getu16 call in
hfs_dir_open_meta_cb in tsk/fs/hfs_dent.c).

CVE-2020-10232

Prevent a stack buffer overflow in yaffsfs_istat by
increasing the buffer size to the size required by tsk_fs_time_to_str.

CVE-2019-1010065

The Sleuth Kit 4.6.0 and earlier is affected by: Integer

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Version: 4.4.0-5+deb9u1
CVE ID: CVE-2017-13755 CVE-2017-13756 CVE-2017-13760 CVE-2018-19497
Debian Bug:

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here