PT-2018-14975 · Tsk+1 · The Sleuth Kit+1

Jordy Zomer

·

Published

2018-11-29

·

Updated

2022-11-29

·

CVE-2018-19497

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions The Sleuth Kit (TSK) versions 4.6.4 and earlier
Description The issue allows attackers to cause a denial of service. It is related to the function hfs cat traverse in tsk/fs/hfs.c, which does not properly determine when a key length is too large. This can lead to a SEGV on an unknown address with READ memory access in a tsk getu16 call in hfs dir open meta cb in tsk/fs/hfs dent.c.
Recommendations For versions 4.6.4 and earlier, as a temporary workaround, consider restricting access to the hfs cat traverse function in tsk/fs/hfs.c until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1222
CVE-2018-19497
DLA-1610-1
DLA-3054-1

Affected Products

Alt Linux
The Sleuth Kit