CVE-2017-13755: Medium severity the sleuth kit vulnerability
Published Aug 29, 2017
·Updated
In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660procdir() in tsk/fs/iso9660dent.c in libtskfs.a, as demonstrated by fls.
Affected Software
2 affected components
sleuthkit The Sleuth Kit=4.4.2
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Aug 29, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-13755?
CVE-2017-13755 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-13755?
To fix CVE-2017-13755, it is recommended to upgrade The Sleuth Kit to version 4.4.3 or later.
3
What types of systems are affected by CVE-2017-13755?
CVE-2017-13755 affects The Sleuth Kit version 4.4.2 and Debian GNU/Linux 9.0.
4
What is the impact of CVE-2017-13755?
The impact of CVE-2017-13755 includes the potential for an out-of-bounds read, which may lead to information disclosure.
5
Is CVE-2017-13755 related to file format vulnerability?
Yes, CVE-2017-13755 is related to a vulnerability in the processing of crafted ISO 9660 images.