PT-2014-2345 · Tsk+1 · The Sleuth Kit+1
Jan Lieskovsky
·
Published
2014-09-29
·
Updated
2021-03-15
·
CVE-2012-5619
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Sleuth Kit (TSK) version 4.0.1
Description
The issue allows local users to hide activities, making it more difficult to conduct forensics activities. This is demonstrated by Flame, where the vulnerability is exploited to conceal certain actions.
Recommendations
For version 4.0.1, consider updating to a newer version that properly handles "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, to prevent local users from hiding activities and making forensics more difficult.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Sleuth Kit
Ubuntu