CVE-2020-10233

Name
CVE-2020-10233
Description
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://github.com/sleuthkit/sleuthkit/issues/1829
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EY53OYU7UZLAJWNIVVNR3EX2RNCCFTB/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AQR2QY3IAF2IG6HGBSKGL66VUDOTC3OA/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FFQKIE5U3LS5U7POPGS7YHLUSW2URWGJ/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:sleuthkit:the_sleuth_kit:*:*:*:*:*:*:*:* the_sleuth_kit >= None <= 4.8.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
sleuthkit edge-community 4.8.0-r1 None fixed
sleuthkit 3.22-community 4.8.0-r1 None fixed
sleuthkit 3.21-community 4.8.0-r1 None fixed
sleuthkit 3.20-community 4.8.0-r1 None fixed
sleuthkit 3.19-community 4.8.0-r1 None fixed
sleuthkit 3.18-community 4.8.0-r1 None fixed
sleuthkit 3.17-community 4.8.0-r1 None fixed