USN-4765-1

Source
https://ubuntu.com/security/notices/USN-4765-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4765-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-4765-1
Related
Published
2021-03-15T20:04:57.650900Z
Modified
2021-03-15T20:04:57.650900Z
Summary
sleuthkit vulnerabilities
Details

It was discovered that The Sleuth Kit did not properly handle certain entires in FAT file systems. An attacker could use this vulnerability to mislead an analyst and obscure their activities. This issue only affected Ubuntu 14.04 ESM. (CVE-2012-5619)

It was discovered that The Sleuth Kit mishandled certain crafted ISO 9660 images. If an analyst were tricked into opening a malicious image, an attacker could cause a denial of service (crash). (CVE-2017-13755)

References

Affected packages

Ubuntu:Pro:14.04:LTS / sleuthkit

Package

Name
sleuthkit
Purl
pkg:deb/ubuntu/sleuthkit@3.2.3-2.2ubuntu0.1~esm1?arch=source&distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2.3-2.2ubuntu0.1~esm1

Affected versions

3.*

3.2.3-2ubuntu1
3.2.3-2ubuntu2
3.2.3-2.1
3.2.3-2.2

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "3.2.3-2.2ubuntu0.1~esm1",
            "binary_name": "libtsk-dev"
        },
        {
            "binary_version": "3.2.3-2.2ubuntu0.1~esm1",
            "binary_name": "libtsk-dev-dbgsym"
        },
        {
            "binary_version": "3.2.3-2.2ubuntu0.1~esm1",
            "binary_name": "libtsk3-3"
        },
        {
            "binary_version": "3.2.3-2.2ubuntu0.1~esm1",
            "binary_name": "libtsk3-3-dbg"
        },
        {
            "binary_version": "3.2.3-2.2ubuntu0.1~esm1",
            "binary_name": "libtsk3-3-dbgsym"
        },
        {
            "binary_version": "3.2.3-2.2ubuntu0.1~esm1",
            "binary_name": "sleuthkit"
        },
        {
            "binary_version": "3.2.3-2.2ubuntu0.1~esm1",
            "binary_name": "sleuthkit-dbgsym"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / sleuthkit

Package

Name
sleuthkit
Purl
pkg:deb/ubuntu/sleuthkit@4.2.0-3ubuntu0.1~esm1?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.2.0-3ubuntu0.1~esm1

Affected versions

4.*

4.1.3-11ubuntu2
4.1.3-12ubuntu1
4.2.0-3

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "binary_version": "4.2.0-3ubuntu0.1~esm1",
            "binary_name": "libtsk-dev"
        },
        {
            "binary_version": "4.2.0-3ubuntu0.1~esm1",
            "binary_name": "libtsk13"
        },
        {
            "binary_version": "4.2.0-3ubuntu0.1~esm1",
            "binary_name": "libtsk13-dbgsym"
        },
        {
            "binary_version": "4.2.0-3ubuntu0.1~esm1",
            "binary_name": "sleuthkit"
        },
        {
            "binary_version": "4.2.0-3ubuntu0.1~esm1",
            "binary_name": "sleuthkit-dbgsym"
        }
    ]
}