Information disclosure in YARA - CVE-2018-12034
Published: August 7, 2018 / Updated: August 8, 2018
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists in the yr_execute_code function, as defined in the source code file libyara/exec.c due to out-of-bounds read. A remote attacker can trick the victim into accessing a YARA rule that submits malicious input, trigger memory corruption and gain access to potentially sensitive information.
Affected software
Fedora
Ubuntu
yara (Ubuntu package)
yara
How to mitigate CVE-2018-12034
yara (Ubuntu package) - addressed in versions 3.4.0+dfsg-2ubuntu0.1~esm1, 3.7.1-1ubuntu2+esm1, 3.9.0-1ubuntu0.1~esm1
yara - addressed in versions 3.8.1-1.el7, 3.8.1-1.fc27, 3.8.1-1.fc28