CVE-2017-8929: Use After Free
Published May 14, 2017
·Updated
The sizedstringcmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule.
Affected Software
1 affected component
VirusTotal yara=3.5.0
Remediation
Patch Available
Event History
May 14, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8929?
CVE-2017-8929 has been classified as a denial of service vulnerability which can lead to application crashes.
2
How do I fix CVE-2017-8929?
To fix CVE-2017-8929, you should upgrade YARA to version 3.5.1 or later where this vulnerability has been addressed.
3
What type of attack does CVE-2017-8929 allow?
CVE-2017-8929 allows remote attackers to execute a denial of service attack through a crafted rule.
4
Which version of YARA is affected by CVE-2017-8929?
CVE-2017-8929 affects YARA version 3.5.0.
5
What function is responsible for the vulnerability in CVE-2017-8929?
The vulnerability in CVE-2017-8929 is due to the sized_string_cmp function in libyara/sizedstr.c.