---
title: "CVE-2012-5619\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-5619?format=md
keywords: index, follow
---

# CVE-2012-5619

Publication date 29 September 2014

Last updated 26 May 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The Sleuth Kit (TSK) 4.0.1 does not properly handle "." (dotfile) file
system entries in FAT file systems and other file systems for which . is
not a reserved name, which allows local users to hide activities it more
difficult to conduct forensics activities, as demonstrated by Flame.

### From the Ubuntu Security Team

It was discovered that The Sleuth Kit did not properly handle certain entires
in FAT file systems. An attacker could use this vulnerability to mislead an
analyst and obscure their activities.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| sleuthkit | 19.04 disco | Not affected |
| 18.10 cosmic | Not affected |
| 18.04 LTS bionic | Not affected |
| 17.10 artful | Not affected |
| 17.04 zesty | Not affected |
| 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.10 utopic | Not affected |
| 14.04 LTS trusty | Fixed 3.2.3-2.2ubuntu0.1~esm1  Ubuntu Pro |
| 13.10 saucy | Ignored end of life |
| 13.04 raring | Ignored end of life |
| 12.10 quantal | Ignored end of life |
| 12.04 LTS precise | Ignored end of life |
| 11.10 oneiric | Ignored end of life |
| 10.04 LTS lucid | Ignored end of life |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5619)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-5619)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-5619)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-5619)

### Related Ubuntu Security Notices (USN)

+ [USN-4765-1](https://usn.ubuntu.com/USN-4765-1)
+ The Sleuth Kit vulnerabilities
+ 15 March 2021

### Other references

* <http://www.openwall.com/lists/oss-security/2012/12/04/2>
* <https://www.cve.org/CVERecord?id=CVE-2012-5619>
