PT-2014-2345 · Tsk+1 · The Sleuth Kit+1
Jan Lieskovsky
·
Publicado
2014-09-29
·
Atualizado
2021-03-15
·
CVE-2012-5619
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Sleuth Kit (TSK) version 4.0.1
Description
The issue allows local users to hide activities, making it more difficult to conduct forensics activities. This is demonstrated by Flame, where the vulnerability is exploited to conceal certain actions.
Recommendations
For version 4.0.1, consider updating to a newer version that properly handles "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, to prevent local users from hiding activities and making forensics more difficult.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
The Sleuth Kit
Ubuntu