CVE-2017-13756: Medium severity the sleuth kit vulnerability
Published Aug 29, 2017
·Updated
In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dosloadexttable() in tsk/vs/dos.c in libtskvs.a, as demonstrated by mmls.
Affected Software
2 affected components
sleuthkit The Sleuth Kit=4.4.2
Debian Debian Linux=9.0
Event History
Aug 29, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-13756?
CVE-2017-13756 is classified with a high severity due to its potential to cause infinite recursion leading to application crashes.
2
How do I fix CVE-2017-13756?
To fix CVE-2017-13756, update The Sleuth Kit to a version newer than 4.4.2 that addresses this vulnerability.
3
What versions of The Sleuth Kit are affected by CVE-2017-13756?
CVE-2017-13756 affects The Sleuth Kit version 4.4.2 and earlier versions.
4
Is CVE-2017-13756 present in Debian's packages?
Yes, CVE-2017-13756 is present in Debian versions that include The Sleuth Kit 4.4.2.
5
What is the impact of exploiting CVE-2017-13756?
Exploiting CVE-2017-13756 can lead to application crashes due to infinite recursion when processing crafted disk images.