Description
In YARA 3.8.1, bytecode in a specially crafted compiled rule can read uninitialized data from VM scratch memory in libyara/exec.c. This can allow attackers to discover addresses in the real stack (not the YARA virtual stack).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-11641 | In YARA 3.8.1, bytecode in a specially crafted compiled rule can read uninitialized data from VM scratch memory in libyara/exec.c. This can allow attackers to discover addresses in the real stack (not the YARA virtual stack). |
Ubuntu USN |
USN-8080-1 | YARA vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:51:17.913Z
Reserved: 2018-12-08T00:00:00.000Z
Link: CVE-2018-19974
No data.
Status : Modified
Published: 2018-12-17T19:29:01.080
Modified: 2024-11-21T03:58:55.210
Link: CVE-2018-19974
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN