5.5
CVSSv3

CVE-2018-19974

Published: 17/12/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

In YARA 3.8.1, bytecode in a specially crafted compiled rule can read uninitialized data from VM scratch memory in libyara/exec.c. This can allow malicious users to discover addresses in the real stack (not the YARA virtual stack).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

virustotal yara 3.8.1

Vendor Advisories

Debian Bug report logs - #916932 yara: CVE-2018-19974, CVE-2018-19975, CVE-2018-19976 Package: yara; Maintainer for yara is Debian Security Tools <team+pkg-security@trackerdebianorg>; Source for yara is src:yara (PTS, buildd, popcon) Reported by: Markus Koschany <apo@debianorg> Date: Thu, 20 Dec 2018 16:21:01 UTC ...