CVE-2020-10233: Critical severity the sleuth kit vulnerability
Published Mar 8, 2020
·Updated
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfsdinodelookup in fs/ntfs.c.
Affected Software
1 affected component
sleuthkit The Sleuth Kit<=4.8.0
Remediation
Patch Available
Event History
Mar 8, 2020
CVE Published
via MITRE·11:52 PM
Data Sourced
via MITRE·11:52 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-10233?
CVE-2020-10233 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2020-10233?
To fix CVE-2020-10233, update The Sleuth Kit to version 4.9.0 or later.
3
What type of vulnerability is CVE-2020-10233?
CVE-2020-10233 is a heap-based buffer over-read vulnerability.
4
Which versions of The Sleuth Kit are affected by CVE-2020-10233?
Versions 4.8.0 and earlier of The Sleuth Kit are affected by CVE-2020-10233.
5
What function is associated with CVE-2020-10233?
The CVE-2020-10233 vulnerability is associated with the ntfs_dinode_lookup function in fs/ntfs.c.