CVE-2018-19497: Debian Linux

Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.

In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is too large, which allows attackers to cause a denial of service (SEGV on unknown address with READ memory access in a tsk_getu16 call in hfs_dir_open_meta_cb in tsk/fs/hfs_dent.c).

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fedoraproject Fedora: version 29 only; version 30 only
  • Sleuthkit The Sleuth Kit: up to and including 4.6.4

Published 2018-11-29. Last modified 2026-06-17.