#VU39100 Out-of-bounds read in YARA - CVE-2017-8294
Published: April 27, 2017 / Updated: January 26, 2021
YARA
VirusTotal
Description
The vulnerability allows a remote attacker to gain access to perform denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the the regex component function in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted rule that is mishandled file. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger out-of-bounds read error and crash the affected application.