The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow. The impact is: Opening crafted disk image triggers crash in tsk/fs/hfsdent.c:237. The component is: Overflow in fls tool used on HFS image. Bug is in tsk/fs/hfs.c file in function hfscat_traverse() in lines: 952, 1062. The attack vector is: Victim must open a crafted HFS filesystem image.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "4.6.5-1", "binary_name": "libtsk-dev" }, { "binary_version": "4.6.5-1", "binary_name": "libtsk13" }, { "binary_version": "4.6.5-1", "binary_name": "libtsk13-dbgsym" }, { "binary_version": "4.6.5-1", "binary_name": "sleuthkit" }, { "binary_version": "4.6.5-1", "binary_name": "sleuthkit-dbgsym" } ] }