Description
The sized_string_cmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: None
Availability: High
Affected Packages3 packages
🔴Vulnerability Details
4OSVyara vulnerabilities↗2026-03-09 ▶ GHSAGHSA-xxqj-m8p7-rjq7: The sized_string_cmp function in libyara/sizedstr↗2022-05-17 ▶ CVEListCVE-2017-8929: The sized_string_cmp function in libyara/sizedstr↗2017-05-14 ▶ OSVCVE-2017-8929: The sized_string_cmp function in libyara/sizedstr↗2017-05-14 ▶ 📋Vendor Advisories
2UbuntuYARA vulnerabilities↗2026-03-09 ▶ DebianCVE-2017-8929: yara - The sized_string_cmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote ...↗2017 ▶ 💬Community
3BugzillaCVE-2017-8929 yara: Use-after-free in sized_string_cmp function↗2017-05-16 ▶ BugzillaCVE-2017-8929 yara: Use-after-free in sized_string_cmp function [fedora-all]↗2017-05-16 ▶ BugzillaCVE-2017-8929 yara: Use-after-free in sized_string_cmp function [epel-all]↗2017-05-16 ▶