First published: Mon Apr 03 2017(Updated: )
libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_parser_lookup_loop_variable function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VirusTotal yara | =3.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10211 has a severity rating that indicates a denial of service risk due to use-after-free vulnerabilities.
CVE-2016-10211 allows remote attackers to exploit YARA 3.5.0, causing a denial of service through crafted rules.
CVE-2016-10211 is characterized by a use-after-free error leading to application crashes.
Updating to a newer version of YARA beyond 3.5.0 is recommended to mitigate CVE-2016-10211.
Check the version of YARA installed; if it is 3.5.0, it is vulnerable to CVE-2016-10211.