In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds read vulnerability in yr_execute_code in libyara/exec.c.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade yara | Jul 30, 2024 | Jun 15, 2018 |
| Ubuntu | — | Upgrade python3-yara (Ubuntu Pro)Upgrade yara (Ubuntu Pro)Upgrade libyara3 (Ubuntu Pro)Upgrade python-yara (Ubuntu Pro) | Mar 10, 2026 | Jun 15, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub