Critical severity9.8NVD Advisory· Published Mar 9, 2020· Updated Jun 17, 2026
CVE-2020-10232
CVE-2020-10232
Description
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:sleuthkit:the_sleuth_kit:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sleuthkit:the_sleuth_kit:*:*:*:*:*:*:*:*range: <=4.8.0
- (no CPE)range: <=4.8.0
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- The Sleuth Kit/The Sleuth Kitdescription
Patches
Vulnerability mechanics
References
6- github.com/sleuthkit/sleuthkit/commit/459ae818fc8dae717549810150de4d191ce158f1nvdPatchThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/03/msg00011.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/06/msg00015.htmlnvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5EY53OYU7UZLAJWNIVVNR3EX2RNCCFTB/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AQR2QY3IAF2IG6HGBSKGL66VUDOTC3OA/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFQKIE5U3LS5U7POPGS7YHLUSW2URWGJ/nvd
News mentions
0No linked articles in our index yet.