PT-2014-2345 · Tsk+1 · The Sleuth Kit+1

Jan Lieskovsky

·

Publicado

2014-09-29

·

Atualizado

2021-03-15

·

CVE-2012-5619

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Sleuth Kit (TSK) version 4.0.1
Description The issue allows local users to hide activities, making it more difficult to conduct forensics activities. This is demonstrated by Flame, where the vulnerability is exploited to conceal certain actions.
Recommendations For version 4.0.1, consider updating to a newer version that properly handles "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, to prevent local users from hiding activities and making forensics more difficult.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-5619
USN-4765-1

Produtos afetados

The Sleuth Kit
Ubuntu