CVE-2018-11738: High severity the sleuth kit vulnerability
An issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function ntfsmakedatarun in tsk/fs/ntfs.c which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service attack.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11738?
CVE-2018-11738 is considered a medium severity vulnerability due to its potential to cause information disclosure through out-of-bounds reads.
How do I fix CVE-2018-11738?
To fix CVE-2018-11738, update The Sleuth Kit to a version later than 4.6.1.
What versions of The Sleuth Kit are affected by CVE-2018-11738?
CVE-2018-11738 affects The Sleuth Kit versions from 4.0.2 to 4.6.1.
Can CVE-2018-11738 lead to remote exploitation?
CVE-2018-11738 does not appear to be directly exploitable for remote attacks, but information disclosure may provide insights that aid in further exploitation.
What component of The Sleuth Kit is impacted by CVE-2018-11738?
CVE-2018-11738 specifically impacts the libtskfs.a component of The Sleuth Kit, particularly in the ntfs_make_data_run function.