OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSleuthkit The Sleuth Kit
APPSleuthkit4.11.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
Related vulnerabilities
CVE-2020-10232CRITICAL9.8PL ✓same product
Stack buffer overflow w The Sleuth Kit – parsowanie znaczników czasu YAFFS
CVE-2020-10233CRITICAL9.1PL ✓same product
Heap-based buffer over-read w The Sleuth Kit przy analizie NTFS
CVE-2019-14531CRITICAL9.8PL ✓same product
Out-of-bounds read w The Sleuth Kit przy parsowaniu obrazów ISO 9660
CVE-2019-14532CRITICAL9.8PL ✓same product
Off-by-one overwrite w The Sleuth Kit (TSK) — błędna tablica skrótów
CVE-2026-40024HIGH8.4same product
The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker t...