PT-2019-11456 · Unknown+1 · The Sleuth Kit+1

Aryabinin

·

Published

2018-08-15

·

Updated

2022-11-29

·

CVE-2019-1010065

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: The Sleuth Kit versions 4.6.0 and earlier
Description: The issue is related to an integer overflow that can cause a crash when opening a crafted disk image. Specifically, the problem lies in the hfs cat traverse() function, located in the tsk/fs/hfs.c file, at lines 952 and 1062. This function is part of the fls tool used on HFS images. The attack vector involves a victim opening a crafted HFS filesystem image, which can trigger the crash.
Recommendations: For versions 4.6.0 and earlier, consider avoiding the use of the fls tool on HFS images until a fix is available. As a temporary workaround, restrict access to the hfs cat traverse() function in the tsk/fs/hfs.c file to minimize the risk of exploitation.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2160
CVE-2019-1010065
DLA-3054-1

Affected Products

Alt Linux
The Sleuth Kit