PT-2021-27514 · Yara · Yara

Published

2021-01-13

·

Updated

2021-01-13

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions: Yara (affected versions not specified)
Description: The issue is related to a heap-use-after-free error, which occurs when the program attempts to access memory that has already been freed. This can lead to a crash. The error is specifically triggered in the yr re ast split at chaining point function, which is called by yr parser reduce string declaration and ultimately by yara yyparse.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

OSV-2018-170

Affected Products

Yara