Home page logo

oss-sec logo oss-sec mailing list archives

CVE request: TSK misrepresents "." files on FAT filesystems
From: Timo Warns <Warns () Pre-Sense DE>
Date: Sat, 1 Dec 2012 21:58:43 +0100

The Sleuth Kit misrepresents files named "." on FAT filesystems. An
attacker could rename a file to "." to evade detection by a forensic

Affected is the current version 4.0.1. Older versions are probably
affected as well.

No patch is currently available. The bug is tracked at

AFAICS, the bug was originally identified by Wim Bertels

Further discussion is at

The vulnerability is already exploited, for example, by the Flame
malware (possibly unintendedly). Flame uses an encrypted SQLite-DB named
"." for extraction of confidential files and for update distribution.
An analyst may miss the file as the Sleuth Kit does not appropriately
show the file.


Regards, Timo

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]