CVE-2018-12034: High severity virustotal vulnerability
Published Jun 15, 2018
·Updated
In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds read vulnerability in yrexecutecode in libyara/exec.c.
Affected Software
1 affected component
VirusTotal yara<=3.7.1
Remediation
Patch Available
Event History
Jun 15, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12034?
CVE-2018-12034 is classified as a medium severity vulnerability due to its potential to allow out of bounds read operations.
2
How do I fix CVE-2018-12034?
To fix CVE-2018-12034, upgrade to YARA version 3.7.2 or later, which addresses this vulnerability.
3
What are the risks associated with CVE-2018-12034?
The risks of CVE-2018-12034 include the potential for information leakage and application crashes due to out of bounds reads.
4
Who is affected by CVE-2018-12034?
CVE-2018-12034 affects users of YARA versions 3.7.1 and earlier, including applications built on that version.
5
How can I determine if I'm vulnerable to CVE-2018-12034?
To determine if you are vulnerable to CVE-2018-12034, check your installed version of YARA against the affected versions.