CVE-2017-8294: High severity virustotal vulnerability
Published Apr 27, 2017
·Updated
libyara/re.c in the regex component in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted rule that is mishandled in the yrreexec function.
Affected Software
1 affected component
VirusTotal yara=3.5.0
Remediation
Patch Available
Event History
Apr 27, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8294?
CVE-2017-8294 is classified as a high severity vulnerability due to its potential for causing denial of service.
2
How do I fix CVE-2017-8294?
To fix CVE-2017-8294, upgrade YARA to the latest version that addresses this vulnerability.
3
What type of attack does CVE-2017-8294 facilitate?
CVE-2017-8294 allows remote attackers to perform denial of service attacks via crafted rules.
4
In which component of YARA is CVE-2017-8294 found?
CVE-2017-8294 is found in the regex component of the libyara library.
5
What software version is affected by CVE-2017-8294?
CVE-2017-8294 specifically affects YARA version 3.5.0.