Brief introduction CVE-2017-13755 . - -------------------------------------------------------------------------Debian LTS Advisory DLA-3054-1
Updated sleuthkit packages fix security vulnerabilities: An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table (CVE-2019-14532). . MGASA-2020-0234 - Updated sleuthkit packages fix security vulnerability Publication date: 27 May 2020 URL: https://advisories.mageia.org/MGASA-2020-0234.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-14532, CVE-2020-10233 Updated sleuthkit packages fix security vulnerabilities: An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table (CVE-2019-14532). In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c (CVE-2020-10233). References: - https://bugs.mageia.org/show_bug.cgi?id=26654 - https://www.cve.org/CVERecord?id=CVE-2019-14532 - https://www.cve.org/CVERecord?id=CVE-2020-10233 SRPMS: - 7/core/sleuthkit-4.9.0-1.mga7 . Recent updates to sleuthkit packages in Mageia tackle significant security issues. Refer to the advisory for comprehensive details and resolution steps.. sleuthkit security, Mageia 2020 security update, security vulnerability fix. . LinuxSecurity.com Team
Update to 4.9.0. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-1dd340ab85 2020-05-17 03:48:03.466953 --------------------------------------------------------------------------------Name : sleuthkit Product : Fedora 31 Version : 4.9.0 Release : 1.fc31 URL : http://www.sleuthkit.org Summary : The Sleuth Kit (TSK) Description : The Sleuth Kit (TSK) is a collection of UNIX-based command line tools that allow you to investigate a computer. The current focus of the tools is the file and volume systems and TSK supports FAT, Ext2/3, NTFS, UFS, and ISO 9660 file systems --------------------------------------------------------------------------------Update Information: Update to 4.9.0 --------------------------------------------------------------------------------ChangeLog: * Fri May 8 2020 Nicolas Chauvet - 4.9.0-1 - Update to 4.9.0 * Tue Jan 28 2020 Nicolas Chauvet - 4.8.0-1 - Update to 4.8.0 * Thu Dec 19 2019 Nicolas Chauvet - 4.7.0-1 - Update to 4.7.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #1752018 - CVE-2019-14532 sleuthkit: sleuth: off-by-one overwrite due to underflow in tools/hashtools/hfind.cpp [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1752018 [ 2 ] Bug #1752019 - CVE-2019-14532 sleuthkit: sleuth: off-by-one overwrite due to underflow in tools/hashtools/hfind.cpp [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1752019 [ 3 ] Bug #1795752 - sleuthkit-4.9.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1795752 [ 4 ] Bug #1811819 - CVE-2020-10232 sleuthkit: Stack buffer overflow vulnerability in yaffsfs_istat() in fs/yaffs.c. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1811819 [ 5 ] Bug #1811820 - CVE-2020-10232 sleuthkit: Stack buffer overflow vulnerability in yaffsfs_istat() in fs/yaffs.c. [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1811820 [ 6 ] Bug #1811823 - CVE-2020-10233 sleuthkit: Heap based buffer overead in in ntfs_dinode_lookup() in fs/ntfs.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1811823 [ 7 ] Bug #1811824 - CVE-2020-10233 sleuthkit: Heap based buffer overead in in ntfs_dinode_lookup() in fs/ntfs.c [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1811824 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-1dd340ab85' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to 4.9.0. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-94c2f78e0c 2020-05-17 02:41:30.102931 --------------------------------------------------------------------------------Name : sleuthkit Product : Fedora 32 Version : 4.9.0 Release : 1.fc32 URL : http://www.sleuthkit.org Summary : The Sleuth Kit (TSK) Description : The Sleuth Kit (TSK) is a collection of UNIX-based command line tools that allow you to investigate a computer. The current focus of the tools is the file and volume systems and TSK supports FAT, Ext2/3, NTFS, UFS, and ISO 9660 file systems --------------------------------------------------------------------------------Update Information: Update to 4.9.0 --------------------------------------------------------------------------------ChangeLog: * Fri May 8 2020 Nicolas Chauvet - 4.9.0-1 - Update to 4.9.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #1752018 - CVE-2019-14532 sleuthkit: sleuth: off-by-one overwrite due to underflow in tools/hashtools/hfind.cpp [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1752018 [ 2 ] Bug #1752019 - CVE-2019-14532 sleuthkit: sleuth: off-by-one overwrite due to underflow in tools/hashtools/hfind.cpp [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1752019 [ 3 ] Bug #1795752 - sleuthkit-4.9.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1795752 [ 4 ] Bug #1811819 - CVE-2020-10232 sleuthkit: Stack buffer overflow vulnerability in yaffsfs_istat() in fs/yaffs.c. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1811819 [ 5 ] Bug #1811820 - CVE-2020-10232 sleuthkit: Stack buffer overflow vulnerability in yaffsfs_istat() in fs/yaffs.c. [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1811820 [ 6 ] Bug #1811823 - CVE-2020-10233 sleuthkit: Heap based buffer overead in inntfs_dinode_lookup() in fs/ntfs.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1811823 [ 7 ] Bug #1811824 - CVE-2020-10233 sleuthkit: Heap based buffer overead in in ntfs_dinode_lookup() in fs/ntfs.c [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1811824 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-94c2f78e0c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Updated sleuthkit packages fix security vulnerability: In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c (CVE-2020-10232). . MGASA-2020-0143 - Updated sleuthkit packages fix security vulnerability Publication date: 18 Mar 2020 URL: https://advisories.mageia.org/MGASA-2020-0143.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-10232 Updated sleuthkit packages fix security vulnerability: In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c (CVE-2020-10232). References: - https://bugs.mageia.org/show_bug.cgi?id=26336 - https://lists.debian.org/debian-lts-announce/2020/03/msg00011.html - https://www.cve.org/CVERecord?id=CVE-2020-10232 SRPMS: - 7/core/sleuthkit-4.6.6-1.1.mga7 . Recent updates to Sleuthkit packages fix a critical stack buffer overflow vulnerability in Mageia 7. This patch boosts security and lowers exploitation risks.. SleuthKit Security Update, Mageia Security Patch, Stack Overflow, File Timestamp Parsing. . Severity: Critical. LinuxSecurity.com Team
Update to 4.6.6 Various bugfixes on the 4.6 branch. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-61b6dae771 2019-06-02 05:40:57.142180 --------------------------------------------------------------------------------Name : sleuthkit Product : Fedora 29 Version : 4.6.6 Release : 1.fc29 URL : http://www.sleuthkit.org Summary : The Sleuth Kit (TSK) Description : The Sleuth Kit (TSK) is a collection of UNIX-based command line tools that allow you to investigate a computer. The current focus of the tools is the file and volume systems and TSK supports FAT, Ext2/3, NTFS, UFS, and ISO 9660 file systems --------------------------------------------------------------------------------Update Information: Update to 4.6.6 Various bugfixes on the 4.6 branch --------------------------------------------------------------------------------ChangeLog: * Fri May 24 2019 Nicolas Chauvet - 4.6.6-1 - Update to 4.6.6 * Tue Mar 26 2019 Nicolas Chauvet - 4.6.5-1 - Update to 4.6.5 * Sat Feb 2 2019 Fedora Release Engineering - 4.6.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1656199 - CVE-2018-19497 sleuthkit: Out-of-bounds memory read in hfs_cat_traverse in tsk/fs/hfs.c [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1656199 [ 2 ] Bug #1656198 - CVE-2018-19497 sleuthkit: Out-of-bounds memory read in hfs_cat_traverse in tsk/fs/hfs.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1656198 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-61b6dae771' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html Allpackages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to 4.6.6 Various bugfixes on the 4.6 branch. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-b860f718ec 2019-06-02 00:53:19.135070 --------------------------------------------------------------------------------Name : sleuthkit Product : Fedora 30 Version : 4.6.6 Release : 1.fc30 URL : http://www.sleuthkit.org Summary : The Sleuth Kit (TSK) Description : The Sleuth Kit (TSK) is a collection of UNIX-based command line tools that allow you to investigate a computer. The current focus of the tools is the file and volume systems and TSK supports FAT, Ext2/3, NTFS, UFS, and ISO 9660 file systems --------------------------------------------------------------------------------Update Information: Update to 4.6.6 Various bugfixes on the 4.6 branch --------------------------------------------------------------------------------ChangeLog: * Fri May 24 2019 Nicolas Chauvet - 4.6.6-1 - Update to 4.6.6 --------------------------------------------------------------------------------References: [ 1 ] Bug #1656199 - CVE-2018-19497 sleuthkit: Out-of-bounds memory read in hfs_cat_traverse in tsk/fs/hfs.c [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1656199 [ 2 ] Bug #1656198 - CVE-2018-19497 sleuthkit: Out-of-bounds memory read in hfs_cat_traverse in tsk/fs/hfs.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1656198 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-b860f718ec' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
It was discovered that the Sleuth Kit (TSK) through version 4.6.4 is affected by a buffer over-read vulnerability. The tsk_getu16 call in hfs_dir_open_meta_cb (tsk/fs/hfs_dent.c) does not properly check boundaries. This vulnerability might be leveraged by remote attackers . Package : sleuthkit Version : 4.1.3-4+deb8u1 CVE ID : CVE-2018-19497 Debian Bug : 914796 It was discovered that the Sleuth Kit (TSK) through version 4.6.4 is affected by a buffer over-read vulnerability. The tsk_getu16 call in hfs_dir_open_meta_cb (tsk/fs/hfs_dent.c) does not properly check boundaries. This vulnerability might be leveraged by remote attackersusing crafted filesystem images to cause denial of service or any other unspecified behavior. For Debian 8 "Jessie", this problem has been fixed in version 4.1.3-4+deb8u1. We recommend that you upgrade your sleuthkit packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Package : sleuthkit Version : 4.1.3-4+deb8u1 CVE ID : CVE-2018-19497 Debian Bug : 914796 It was disc. sleuth, (tsk), through, version, affected, buffer, over-read. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.