383
VMScore

CVE-2018-19976

Published: 17/12/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara/exec.c. This is a consequence of the design of the YARA virtual machine.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

virustotal yara 3.8.1

Vendor Advisories

Debian Bug report logs - #916932 yara: CVE-2018-19974, CVE-2018-19975, CVE-2018-19976 Package: yara; Maintainer for yara is Debian Security Tools <team+pkg-security@trackerdebianorg>; Source for yara is src:yara (PTS, buildd, popcon) Reported by: Markus Koschany <apo@debianorg> Date: Thu, 20 Dec 2018 16:21:01 UTC ...