In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds write vulnerability in yr_execute_code in libyara/exec.c.
CVSS Details
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade yara | Jul 30, 2024 | Jun 15, 2018 |
| Ubuntu | — | Upgrade libyara3 (Ubuntu Pro)Upgrade yara (Ubuntu Pro)Upgrade python-yara (Ubuntu Pro)Upgrade python3-yara (Ubuntu Pro) | Mar 10, 2026 | Jun 15, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub