Mageia 2020-0234: sleuthkit security update
Summary
Updated sleuthkit packages fix security vulnerabilities:
An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an
off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp
while using a bogus hash table (CVE-2019-14532).
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a
heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c
(CVE-2020-10233).
References
- https://bugs.mageia.org/show_bug.cgi?id=26654
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14532
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10233
Resolution
MGASA-2020-0234 - Updated sleuthkit packages fix security vulnerability
SRPMS
- 7/core/sleuthkit-4.9.0-1.mga7