CVE-2018-19497: Medium severity the sleuth kit vulnerability
In The Sleuth Kit (TSK) through 4.6.4, hfscattraverse in tsk/fs/hfs.c does not properly determine when a key length is too large, which allows attackers to cause a denial of service (SEGV on unknown address with READ memory access in a tskgetu16 call in hfsdiropenmetacb in tsk/fs/hfsdent.c).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19497?
CVE-2018-19497 is classified as a denial of service vulnerability.
How do I fix CVE-2018-19497?
To fix CVE-2018-19497, update The Sleuth Kit to version 4.6.5 or later.
Which software is affected by CVE-2018-19497?
CVE-2018-19497 affects The Sleuth Kit versions up to and including 4.6.4, as well as specific versions of Debian and Fedora.
What type of attack is associated with CVE-2018-19497?
CVE-2018-19497 can be exploited to cause a segmentation fault, leading to a denial of service.
Can CVE-2018-19497 be exploited remotely?
While CVE-2018-19497 does not specify remote exploitation, it enables denial of service through improper key length handling.