MGASA-2020-0143

Source
https://advisories.mageia.org/MGASA-2020-0143.html
Import Source
https://advisories.mageia.org/MGASA-2020-0143.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2020-0143
Related
Published
2020-03-18T15:27:39Z
Modified
2020-03-18T14:59:49Z
Summary
Updated sleuthkit packages fix security vulnerability
Details

Updated sleuthkit packages fix security vulnerability:

In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c (CVE-2020-10232).

References
Credits

Affected packages

Mageia:7 / sleuthkit

Package

Name
sleuthkit
Purl
pkg:rpm/mageia/sleuthkit?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.6.6-1.1.mga7

Ecosystem specific

{
    "section": "core"
}