In version 4
In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c.
Exploitability
AV:N
AC:L
PR:N
UI:N
Scope
S:U
Impact
C:H
I:N
A:H
9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H