SB2020031333 - Out-of-bounds write in sleuthkit (Alpine package)
Published: March 13, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2020-10232)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c.
Remediation
Install update from vendor's website.