First published: Tue Aug 29 2017(Updated: )
In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as demonstrated by mmls.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
The Sleuth Kit | =4.4.2 | |
Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-13756 is classified with a high severity due to its potential to cause infinite recursion leading to application crashes.
To fix CVE-2017-13756, update The Sleuth Kit to a version newer than 4.4.2 that addresses this vulnerability.
CVE-2017-13756 affects The Sleuth Kit version 4.4.2 and earlier versions.
Yes, CVE-2017-13756 is present in Debian versions that include The Sleuth Kit 4.4.2.
Exploiting CVE-2017-13756 can lead to application crashes due to infinite recursion when processing crafted disk images.