Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2018-11740
Disclosure Date: June 05, 2018 (last updated November 26, 2024)
An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function tsk_UTF16toUTF8 in tsk/base/tsk_unicode.c which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service attack.
0
Attacker Value
Unknown
CVE-2017-13760
Disclosure Date: August 29, 2017 (last updated November 26, 2024)
In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_io.c in libtskimg.a.
0
Attacker Value
Unknown
CVE-2017-13756
Disclosure Date: August 29, 2017 (last updated November 26, 2024)
In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as demonstrated by mmls.
0
Attacker Value
Unknown
CVE-2017-13755
Disclosure Date: August 29, 2017 (last updated November 26, 2024)
In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in tsk/fs/iso9660_dent.c in libtskfs.a, as demonstrated by fls.
0
Attacker Value
Unknown
CVE-2012-5619
Disclosure Date: September 29, 2014 (last updated October 05, 2023)
The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows local users to hide activities it more difficult to conduct forensics activities, as demonstrated by Flame.
0
Attacker Value
Unknown
CVE-2007-4195
Disclosure Date: August 08, 2007 (last updated October 04, 2023)
Use-after-free vulnerability in ext2fs.c in Brian Carrier The Sleuth Kit (TSK) before 2.09 allows user-assisted remote attackers to cause a denial of service (application crash) and prevent examination of certain ext2fs files via a malformed ext2fs image.
0
Attacker Value
Unknown
CVE-2007-2799
Disclosure Date: May 23, 2007 (last updated October 04, 2023)
Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted attackers to execute arbitrary code via a large file that triggers an overflow that bypasses an assert() statement. NOTE: this issue is due to an incorrect patch for CVE-2007-1536.
0