PT-2018-10955 · Yara · Yara

Bnbdrop

·

Published

2018-06-15

·

Updated

2026-03-09

·

CVE-2018-12034

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions YARA versions prior to 3.7.1
Description The issue arises when parsing a specially crafted compiled rule file, leading to an out of bounds read in the yr execute code function located in libyara/exec.c.
Recommendations For versions prior to 3.7.1, update to version 3.7.1 or later to resolve the issue.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2018-12034
USN-8080-1

Affected Products

Yara