Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown

CVE-2018-11740

Disclosure Date: June 05, 2018 (last updated November 26, 2024)
An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function tsk_UTF16toUTF8 in tsk/base/tsk_unicode.c which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service attack.
0
Attacker Value
Unknown

CVE-2017-13760

Disclosure Date: August 29, 2017 (last updated November 26, 2024)
In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_io.c in libtskimg.a.
Attacker Value
Unknown

CVE-2017-13756

Disclosure Date: August 29, 2017 (last updated November 26, 2024)
In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as demonstrated by mmls.
Attacker Value
Unknown

CVE-2017-13755

Disclosure Date: August 29, 2017 (last updated November 26, 2024)
In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in tsk/fs/iso9660_dent.c in libtskfs.a, as demonstrated by fls.
Attacker Value
Unknown

CVE-2012-5619

Disclosure Date: September 29, 2014 (last updated October 05, 2023)
The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows local users to hide activities it more difficult to conduct forensics activities, as demonstrated by Flame.
0
Attacker Value
Unknown

CVE-2007-4195

Disclosure Date: August 08, 2007 (last updated October 04, 2023)
Use-after-free vulnerability in ext2fs.c in Brian Carrier The Sleuth Kit (TSK) before 2.09 allows user-assisted remote attackers to cause a denial of service (application crash) and prevent examination of certain ext2fs files via a malformed ext2fs image.
0
Attacker Value
Unknown

CVE-2007-2799

Disclosure Date: May 23, 2007 (last updated October 04, 2023)
Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted attackers to execute arbitrary code via a large file that triggers an overflow that bypasses an assert() statement. NOTE: this issue is due to an incorrect patch for CVE-2007-1536.
0