CVE-2012-5619
published 2014-09-29CVE-2012-5619: The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.35%
27.6th percentile
The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows local users to hide activities it more difficult to conduct forensics activities, as demonstrated by Flame.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sleuthkit | < sleuthkit 4.1.2-1 (bookworm) | sleuthkit 4.1.2-1 (bookworm) |
| sleuthkit | sleuthkit | >= 0 < 4.1.2-1 | 4.1.2-1 |
| sleuthkit | sleuthkit | >= 0 < 4.1.2-1 | 4.1.2-1 |
| sleuthkit | sleuthkit | >= 0 < 4.1.2-1 | 4.1.2-1 |
| sleuthkit | sleuthkit | >= 0 < 4.1.2-1 | 4.1.2-1 |
| sleuthkit | sleuthkit | >= 0 < 3.2.3-2.2ubuntu0.1~esm1 | 3.2.3-2.2ubuntu0.1~esm1 |
| sleuthkit | sleuthkit | >= 0 < 4.2.0-3ubuntu0.1~esm1 | 4.2.0-3ubuntu0.1~esm1 |
| sleuthkit | the_sleuth_kit | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4wj6-2665-qg48: The Sleuth Kit (TSK) 4
ghsa_unreviewed·2022-05-17
CVE-2012-5619 [LOW] CWE-20 GHSA-4wj6-2665-qg48: The Sleuth Kit (TSK) 4
The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows local users to hide activities it more difficult to conduct forensics activities, as demonstrated by Flame.
OSV
sleuthkit vulnerabilities
osv·2021-03-15·CVSS 2.1
CVE-2012-5619 [LOW] sleuthkit vulnerabilities
sleuthkit vulnerabilities
It was discovered that The Sleuth Kit did not properly handle certain
entires in FAT file systems. An attacker could use this vulnerability to
mislead an analyst and obscure their activities. This issue only affected
Ubuntu 14.04 ESM. (CVE-2012-5619)
It was discovered that The Sleuth Kit mishandled certain crafted ISO 9660
images. If an analyst were tricked into opening a malicious image, an
attacker could cause a denial of service (crash). (CVE-2017-13755)
OSV
CVE-2012-5619: The Sleuth Kit (TSK) 4
osv·2014-09-29·CVSS 2.1
CVE-2012-5619 [LOW] CVE-2012-5619: The Sleuth Kit (TSK) 4
The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows local users to hide activities it more difficult to conduct forensics activities, as demonstrated by Flame.
Ubuntu
The Sleuth Kit vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 2.1
CVE-2012-5619 [LOW] The Sleuth Kit vulnerabilities
Title: The Sleuth Kit vulnerabilities
Summary: Several security issues were fixed in the Sleuth Kit.
It was discovered that The Sleuth Kit did not properly handle certain
entires in FAT file systems. An attacker could use this vulnerability to
mislead an analyst and obscure their activities. This issue only affected
Ubuntu 14.04 ESM. (CVE-2012-5619)
It was discovered that The Sleuth Kit mishandled certain crafted ISO 9660
images. If an analyst were tricked into opening a malicious image, an
attacker could cause a denial of service (crash). (CVE-2017-13755)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2012-5619: sleuthkit - The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system en...
vendor_debian·2012·CVSS 2.1
CVE-2012-5619 [LOW] CVE-2012-5619: sleuthkit - The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system en...
The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows local users to hide activities it more difficult to conduct forensics activities, as demonstrated by Flame.
Scope: local
bookworm: resolved (fixed in 4.1.2-1)
bullseye: resolved (fixed in 4.1.2-1)
forky: resolved (fixed in 4.1.2-1)
sid: resolved (fixed in 4.1.2-1)
trixie: resolved (fixed in 4.1.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5619 sleuthkit: Improper interpretation of '.' entry on FAT filesystems (possibility to evade detection by forensic analysis) [fedora-all]
bugzilla·2012-12-04·CVSS 2.1
CVE-2012-5619 [LOW] CVE-2012-5619 sleuthkit: Improper interpretation of '.' entry on FAT filesystems (possibility to evade detection by forensic analysis) [fedora-all]
CVE-2012-5619 sleuthkit: Improper interpretation of '.' entry on FAT filesystems (possibility to evade detection by forensic analysis) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog
Bugzilla
CVE-2012-5619 sleuthkit: Improper interpretation of '.' entry on FAT filesystems (possibility to evade detection by forensic analysis)
bugzilla·2012-12-04·CVSS 2.1
CVE-2012-5619 [LOW] CVE-2012-5619 sleuthkit: Improper interpretation of '.' entry on FAT filesystems (possibility to evade detection by forensic analysis)
CVE-2012-5619 sleuthkit: Improper interpretation of '.' entry on FAT filesystems (possibility to evade detection by forensic analysis)
A security flaw was found in the way the Sleuth Kit (TSK), a collection of UNIX-based command line tools allowing to investigate a computer, performed management of '.' (dotfile) file system entry. An attacker could use this flaw to evade detection by forensic analysis (hide certain files not to be scanned) by renaming the file in question it to be '.' file system entry.
The original reports speaks about this attack vector to be present when scanning FAT (File Allocation Table) file system. It is possible though, the flaw to be present on other file systems, which do not reserve usage of '.' entry for special purpose, too.
References:
[1] http://www.open
http://labs.bitdefender.com/2012/06/flame-the-story-of-leaked-data-carried-by-human-vector/http://lists.fedoraproject.org/pipermail/package-announce/2013-January/097289.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-January/097293.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:125http://www.openwall.com/lists/oss-security/2012/12/01/2http://www.openwall.com/lists/oss-security/2012/12/04/2https://bugzilla.redhat.com/show_bug.cgi?id=883330http://labs.bitdefender.com/2012/06/flame-the-story-of-leaked-data-carried-by-human-vector/http://lists.fedoraproject.org/pipermail/package-announce/2013-January/097289.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-January/097293.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2013:125http://www.openwall.com/lists/oss-security/2012/12/01/2http://www.openwall.com/lists/oss-security/2012/12/04/2https://bugzilla.redhat.com/show_bug.cgi?id=883330
2014-09-29
Published