OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.
oryginał ENCVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSleuthkit The Sleuth Kit
APPSleuthkit4.11.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Command Injection
Powiązane podatności
CVE-2020-10232CRITICAL9.8PL ✓ten sam produkt
Stack buffer overflow w The Sleuth Kit – parsowanie znaczników czasu YAFFS
CVE-2020-10233CRITICAL9.1PL ✓ten sam produkt
Heap-based buffer over-read w The Sleuth Kit przy analizie NTFS
CVE-2019-14531CRITICAL9.8PL ✓ten sam produkt
Out-of-bounds read w The Sleuth Kit przy parsowaniu obrazów ISO 9660
CVE-2019-14532CRITICAL9.8PL ✓ten sam produkt
Off-by-one overwrite w The Sleuth Kit (TSK) — błędna tablica skrótów
CVE-2026-40024HIGH8.4ten sam produkt
The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker t...