9.8
CVSSv3

CVE-2020-10232

Published: 09/03/2020 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In version 4.8.0 and previous versions of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sleuthkit the sleuth kit

debian debian linux 8.0

debian debian linux 9.0

fedoraproject fedora 30

fedoraproject fedora 31

fedoraproject fedora 32

Vendor Advisories

Debian Bug report logs - #953976 sleuthkit: CVE-2020-10232 Package: src:sleuthkit; Maintainer for src:sleuthkit is Debian Security Tools <team+pkg-security@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 15 Mar 2020 09:24:01 UTC Severity: important Tags: security, upstream Found ...