mailing list archives
CVE request: TSK misrepresents "." files on FAT filesystems
From: Timo Warns <Warns () Pre-Sense DE>
Date: Sat, 1 Dec 2012 21:58:43 +0100
The Sleuth Kit misrepresents files named "." on FAT filesystems. An
attacker could rename a file to "." to evade detection by a forensic
Affected is the current version 4.0.1. Older versions are probably
affected as well.
No patch is currently available. The bug is tracked at
AFAICS, the bug was originally identified by Wim Bertels
Further discussion is at
The vulnerability is already exploited, for example, by the Flame
malware (possibly unintendedly). Flame uses an encrypted SQLite-DB named
"." for extraction of confidential files and for update distribution.
An analyst may miss the file as the Sleuth Kit does not appropriately
show the file.
- CVE request: TSK misrepresents "." files on FAT filesystems Timo Warns (Dec 01)