CVE-2012-5619

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
29/09/2014
Last modified:
12/04/2025

Description

The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file system entries in FAT file systems and other file systems for which . is not a reserved name, which allows local users to hide activities it more difficult to conduct forensics activities, as demonstrated by Flame.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sleuthkit:the_sleuth_kit:4.0.1:*:*:*:*:*:*:*