The Sleuth Kit
cpe:2.3:a:sleuthkit:the_sleuth_kit:*:*:*:*:*:*:*
- <= 4.14.0
A out-of-bounds read vulnerability has been identified in The Sleuth Kit versions through 4.14.0, within the ISO9660 filesystem parser. The issue arises in the parse_susp() function, which improperly trusts the len_id, len_des, and len_src fields from the disk image. This lack of validation allows data to be copied into a stack buffer using memcpy, potentially leading to reads beyond the intended SUSP data buffer. Additionally, a zero-length SUSP entry can cause an infinite parsing loop.
Exploitation of this vulnerability can lead to out-of-bounds read, causing potential information disclosure or memory corruption.
Users can update to The Sleuth Kit version 4.14.0 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.