First published: Fri Jun 15 2018(Updated: )
In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds read vulnerability in yr_execute_code in libyara/exec.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VirusTotal yara | <=3.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12034 is classified as a medium severity vulnerability due to its potential to allow out of bounds read operations.
To fix CVE-2018-12034, upgrade to YARA version 3.7.2 or later, which addresses this vulnerability.
The risks of CVE-2018-12034 include the potential for information leakage and application crashes due to out of bounds reads.
CVE-2018-12034 affects users of YARA versions 3.7.1 and earlier, including applications built on that version.
To determine if you are vulnerable to CVE-2018-12034, check your installed version of YARA against the affected versions.