CVE-2018-12035 — Out-of-bounds Write in Yara
Severity
7.8HIGHNVD
OSV7.5
EPSS
0.2%
top 60.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 15
Latest updateMar 9
Description
In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds write vulnerability in yr_execute_code in libyara/exec.c.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages3 packages
Patches
🔴Vulnerability Details
4📋Vendor Advisories
2💬Community
3Bugzilla▶
CVE-2018-12035 yara: out of bounds write in yr_execute_code in libyara/exec.c [fedora-all]↗2018-06-15
Bugzilla
▶