Vulnerability identifier: #VU19932
Vulnerability risk: Medium
CVSSv3.1: 5.9 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-404
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
YARA
Server applications /
Server solutions for antivurus protection
Vendor: VirusTotal
Description
Mitigation
Install updates from vendor's website.
Vulnerable software versions
YARA: 3.8.1
External links
http://talosintelligence.com/vulnerability_reports/TALOS-2019-0781
http://github.com/virustotal/yara/releases/tag/v3.10.0
http://github.com/VirusTotal/yara/commit/1ecb0e66431bf5c5b4c2fdf622be969eb5f4a7cc
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.