#VU14222 Information disclosure in YARA - CVE-2018-12034
Published: August 7, 2018 / Updated: August 8, 2018
YARA
VirusTotal
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists in the yr_execute_code function, as defined in the source code file libyara/exec.c due to out-of-bounds read. A remote attacker can trick the victim into accessing a YARA rule that submits malicious input, trigger memory corruption and gain access to potentially sensitive information.