Vulnerability Description
The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from process memory via a crafted file that is mishandled in the yr_re_fast_exec function in libyara/re.c and the _yr_scan_match_callback function in libyara/scan.c.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Virustotal | Yara | 3.6.1 |
Related Weaknesses (CWE)
References
- https://github.com/VirusTotal/yara/commit/992480c30f75943e9cd6245bb2015c7737f9b6PatchThird Party Advisory
- https://github.com/VirusTotal/yara/issues/678ExploitThird Party Advisory
- https://github.com/VirusTotal/yara/commit/992480c30f75943e9cd6245bb2015c7737f9b6PatchThird Party Advisory
- https://github.com/VirusTotal/yara/issues/678ExploitThird Party Advisory
FAQ
What is CVE-2017-9465?
CVE-2017-9465 is a vulnerability with a CVSS score of 7.1 (HIGH). The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from process memory via a c...
How severe is CVE-2017-9465?
CVE-2017-9465 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9465?
Check the references section above for vendor advisories and patch information. Affected products include: Virustotal Yara.