CVE-2017-13755: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.

In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in tsk/fs/iso9660_dent.c in libtskfs.a, as demonstrated by fls.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Sleuthkit The Sleuth Kit: version 4.4.2 only

Published 2017-08-29. Last modified 2026-06-17.