In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c.
{ "vanir_signatures": [ { "id": "CVE-2020-10232-7d89f174", "signature_version": "v1", "source": "https://github.com/sleuthkit/sleuthkit/commit/459ae818fc8dae717549810150de4d191ce158f1", "target": { "function": "yaffsfs_istat", "file": "tsk/fs/yaffs.cpp" }, "deprecated": false, "digest": { "function_hash": "263724667031508014577914061865834071996", "length": 2898.0 }, "signature_type": "Function" }, { "id": "CVE-2020-10232-e06d7a8c", "signature_version": "v1", "source": "https://github.com/sleuthkit/sleuthkit/commit/459ae818fc8dae717549810150de4d191ce158f1", "target": { "file": "tsk/fs/yaffs.cpp" }, "deprecated": false, "digest": { "line_hashes": [ "229477867235996326580794300073845982637", "315498531788442505570037119712918689127", "71916475094926165661512058954710082462", "260045061982410582454978425116972741467" ], "threshold": 0.9 }, "signature_type": "Line" } ] }