PT-2019-13740 · Tsk+2 · The Sleuth Kit+2

Nico Waisman

·

Published

2019-08-02

·

Updated

2022-04-22

·

CVE-2019-14532

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Sleuth Kit (TSK) version 4.6.6
Description An issue was discovered in The Sleuth Kit (TSK) where there is an off-by-one overwrite due to an underflow. This occurs in the hfind.cpp file, specifically when using a bogus hash table in the tools/hashtools directory.
Recommendations For version 4.6.6, consider restricting access to the hfind.cpp tool until a patch is available. As a temporary workaround, avoid using the hfind tool with bogus hash tables to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2661
CVE-2019-14532
MGASA-2020-0234

Affected Products

Alt Linux
Debian
The Sleuth Kit