Candidate: CVE-2019-1010065 PublicDate: 2019-07-18 17:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1010065 https://github.com/sleuthkit/sleuthkit/commit/114cd3d0aac8bd1aeaf4b33840feb0163d342d5b https://issuetracker.google.com/issues/77809383 Description: The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow. The impact is: Opening crafted disk image triggers crash in tsk/fs/hfs_dent.c:237. The component is: Overflow in fls tool used on HFS image. Bug is in tsk/fs/hfs.c file in function hfs_cat_traverse() in lines: 952, 1062. The attack vector is: Victim must open a crafted HFS filesystem image. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_sleuthkit: upstream_sleuthkit: released (4.6.1-1) precise/esm_sleuthkit: DNE trusty_sleuthkit: ignored (out of standard support) trusty/esm_sleuthkit: DNE xenial_sleuthkit: ignored (end of standard support, was needed) bionic_sleuthkit: needed disco_sleuthkit: not-affected (4.6.5-1) eoan_sleuthkit: not-affected (4.6.5-1) focal_sleuthkit: not-affected (4.6.5-1) groovy_sleuthkit: not-affected (4.6.5-1) hirsute_sleuthkit: not-affected (4.6.5-1) impish_sleuthkit: not-affected (4.6.5-1) jammy_sleuthkit: not-affected (4.6.5-1) devel_sleuthkit: not-affected (4.6.5-1)