VDB

CVE-2019-1010065

CVE-2019-1010065 PUBLISHED CVSS 6.5 MEDIUM

The Sleuth Kit 4.6.0 and earlier is affected by: Integer Overflow. The impact is: Opening crafted disk image triggers crash in tsk/fs/hfs_dent.c:237. The component is: Overflow in fls tool used on HFS image. Bug is in tsk/fs/hfs.c file in function hfs_cat_traverse() in lines: 952, 1062. The attack vector is: Victim must open a crafted HFS filesystem image.

EPSS 1.37% · 70.0th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
1.37%
70.0th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSsleuthkit3.2.3-2.1, 3.2.3-2.2, 3.2.3-2.2ubuntu0.1~esm1
Ubuntu:18.04:LTSsleuthkit0, 4.4.2-1, 4.4.2-3
Ubuntu:Pro:16.04:LTSsleuthkit0, 4.2.0-3, 4.2.0-3ubuntu0.1~esm1

Timeline

  • Jul 18, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 28, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Sep 6, 2022 EPSS Score
  • Nov 7, 2022 EPSS Score
  • Jan 9, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›