CVE-2016-10211: Use After Free
Published Apr 3, 2017
·Updated
libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yrparserlookuploopvariable function.
Affected Software
1 affected component
VirusTotal yara=3.5.0
Remediation
Patch Available
Event History
Apr 3, 2017
CVE Published
via MITRE·05:44 AM
Data Sourced
via MITRE·05:44 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10211?
CVE-2016-10211 has a severity rating that indicates a denial of service risk due to use-after-free vulnerabilities.
2
How does CVE-2016-10211 affect YARA 3.5.0?
CVE-2016-10211 allows remote attackers to exploit YARA 3.5.0, causing a denial of service through crafted rules.
3
What is the nature of the vulnerability in CVE-2016-10211?
CVE-2016-10211 is characterized by a use-after-free error leading to application crashes.
4
Is there a fix available for CVE-2016-10211?
Updating to a newer version of YARA beyond 3.5.0 is recommended to mitigate CVE-2016-10211.
5
How can I verify if my YARA installation is affected by CVE-2016-10211?
Check the version of YARA installed; if it is 3.5.0, it is vulnerable to CVE-2016-10211.