Description
In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size. A specially crafted MachO file can cause an out-of-bounds memory access, resulting in Denial of Service (application crash) or potential code execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-9258 | In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size. A specially crafted MachO file can cause an out-of-bounds memory access, resulting in Denial of Service (application crash) or potential code execution. |
Ubuntu USN |
USN-8080-1 | YARA vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:25:12.181Z
Reserved: 2019-12-09T00:00:00.000Z
Link: CVE-2019-19648
No data.
Status : Modified
Published: 2019-12-09T01:15:10.357
Modified: 2024-11-21T04:35:07.723
Link: CVE-2019-19648
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Ubuntu USN