#VU39300 Use-after-free in YARA - CVE-2016-10211
Published: April 3, 2017 / Updated: January 26, 2021
YARA
VirusTotal
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing a crafted rule that is mishandled in the yr_parser_lookup_loop_variable function. A remote attackers can cause a denial of service (use-after-free and application crash).
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.