MGASA-2020-0234 - Updated sleuthkit packages fix security vulnerability

Publication date: 27 May 2020
URL: https://advisories.mageia.org/MGASA-2020-0234.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-14532,
     CVE-2020-10233

Updated sleuthkit packages fix security vulnerabilities:

An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an
off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp
while using a bogus hash table (CVE-2019-14532).

In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a
heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c
(CVE-2020-10233).

References:
- https://bugs.mageia.org/show_bug.cgi?id=26654
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14532
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10233

SRPMS:
- 7/core/sleuthkit-4.9.0-1.mga7

Mageia 2020-0234: sleuthkit security update

Updated sleuthkit packages fix security vulnerabilities: An issue was discovered in The Sleuth Kit (TSK) 4.6.6

Summary

Updated sleuthkit packages fix security vulnerabilities:
An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table (CVE-2019-14532).
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c (CVE-2020-10233).

References

- https://bugs.mageia.org/show_bug.cgi?id=26654

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14532

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10233

Resolution

MGASA-2020-0234 - Updated sleuthkit packages fix security vulnerability

SRPMS

- 7/core/sleuthkit-4.9.0-1.mga7

Severity
Publication date: 27 May 2020
URL: https://advisories.mageia.org/MGASA-2020-0234.html
Type: security
CVE: CVE-2019-14532, CVE-2020-10233

Related News