CVE-2018-11740
NONE
Published Jun 5, 20188y ago · Modified Jun 17, 20261w ago
Published Jun 5, 2018 8y ago
Last Modified Jun 17, 2026 1w ago
Description
An issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found in the function tsk_UTF16toUTF8 in tsk/base/tsk_unicode.c which could be leveraged by an attacker to disclose information or manipulated to read from unmapped memory causing a denial of service attack.
Threat Intelligence
No active exploitation signals — not in CISA KEV and no EPSS score yet.
Exploit & Patch Status
Public Exploit Known
Patch Available
Weaknesses 1
CWE-125 Out-of-bounds Read Memory Safety
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| sleuthkit | the_sleuth_kit | * | ≥4.0.2 – ≤4.6.1 |
References 1
- github.com https://github.com/sleuthkit/sleuthkit/issues/1264
Remediation
- github.com https://github.com/sleuthkit/sleuthkit/issues/1264