Back to search
CVE-2007-4198
Published: Aug 8, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
The fs_data_put_str function in ntfs.c in fls in Brian Carrier The Sleuth Kit (TSK) before 2.09 does not validate a certain length value, which allows user-assisted remote attackers to cause a denial of service (application crash) and prevent examination of certain NTFS files via a malformed NTFS image, which triggers a buffer over-read.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20070726 Re: Guidance Software response to iSEC report on EnCase
mailing-list
x_refsource_BUGTRAQ
46998
vdb-entry
x_refsource_OSVDB
25181
vdb-entry
x_refsource_BID
20070802 RE: Re: Guidance Software response to iSEC report on EnCase
mailing-list
x_refsource_BUGTRAQ
[sleuthkit-announce] 20070614 TSK 2.09 Released and new Wiki
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now