CVE Vulnerabilities

CVE-2017-13756

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Aug 29, 2017 | Modified: Nov 29, 2022
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
NEGLIGIBLE

In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as demonstrated by mmls.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
The_sleuth_kit Sleuthkit 4.4.2 (including) 4.4.2 (including)
Sleuthkit Ubuntu artful *
Sleuthkit Ubuntu esm-apps/xenial *
Sleuthkit Ubuntu esm-infra-legacy/trusty *
Sleuthkit Ubuntu trusty *
Sleuthkit Ubuntu trusty/esm *
Sleuthkit Ubuntu upstream *
Sleuthkit Ubuntu xenial *
Sleuthkit Ubuntu zesty *

References