CVE-2019-14532: Critical severity the sleuth kit vulnerability
Published Aug 2, 2019
·Updated
An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table.
Affected Software
4 affected components
sleuthkit The Sleuth Kit=4.6.6
Fedoraproject Fedora=30
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Event History
Aug 2, 2019
CVE Published
via MITRE·02:07 PM
Data Sourced
via MITRE·02:07 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-14532?
CVE-2019-14532 has a medium severity rating due to its potential for triggering an off-by-one overwrite vulnerability.
2
How do I fix CVE-2019-14532?
To fix CVE-2019-14532, update The Sleuth Kit to the latest version that addresses the vulnerability.
3
Which software versions are affected by CVE-2019-14532?
CVE-2019-14532 affects The Sleuth Kit version 4.6.6 and specific Fedora versions 30, 31, and 32.
4
What type of vulnerability is CVE-2019-14532?
CVE-2019-14532 is characterized as an off-by-one overwrite vulnerability due to an underflow error.
5
Is CVE-2019-14532 a critical vulnerability?
CVE-2019-14532 is not classified as critical but should be addressed due to its potential risks.