MGASA-2020-0234

Source
https://advisories.mageia.org/MGASA-2020-0234.html
Import Source
https://advisories.mageia.org/MGASA-2020-0234.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2020-0234
Related
Published
2020-05-27T09:52:46Z
Modified
2020-05-27T09:21:27Z
Summary
Updated sleuthkit packages fix security vulnerability
Details

Updated sleuthkit packages fix security vulnerabilities:

An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table (CVE-2019-14532).

In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfsdinodelookup in fs/ntfs.c (CVE-2020-10233).

References
Credits

Affected packages

Mageia:7 / sleuthkit

Package

Name
sleuthkit
Purl
pkg:rpm/mageia/sleuthkit?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.9.0-1.mga7

Ecosystem specific

{
    "section": "core"
}