CVE-2018-11737: High severity the sleuth kit vulnerability
Published Jun 5, 2018
·Updated
An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function ntfsfixidxrec in tsk/fs/ntfsdent.cpp which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service.
Affected Software
1 affected component
sleuthkit The Sleuth Kit>=4.0.2<=4.6.1
Remediation
Patch Available
Event History
Jun 5, 2018
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11737?
CVE-2018-11737 is rated as a medium severity vulnerability.
2
What is the impact of CVE-2018-11737 on affected systems?
CVE-2018-11737 can lead to an out-of-bounds read, potentially disclosing sensitive information.
3
How do I fix CVE-2018-11737?
To mitigate CVE-2018-11737, update The Sleuth Kit to a version later than 4.6.1.
4
Which versions of The Sleuth Kit are affected by CVE-2018-11737?
CVE-2018-11737 affects The Sleuth Kit versions from 4.0.2 to 4.6.1 inclusive.
5
What components of The Sleuth Kit are involved in CVE-2018-11737?
CVE-2018-11737 specifically involves the libtskfs.a component in The Sleuth Kit.