First published: Sun May 14 2017(Updated: )
The sized_string_cmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VirusTotal yara | =3.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8929 has been classified as a denial of service vulnerability which can lead to application crashes.
To fix CVE-2017-8929, you should upgrade YARA to version 3.5.1 or later where this vulnerability has been addressed.
CVE-2017-8929 allows remote attackers to execute a denial of service attack through a crafted rule.
CVE-2017-8929 affects YARA version 3.5.0.
The vulnerability in CVE-2017-8929 is due to the sized_string_cmp function in libyara/sizedstr.c.