Heap-based Out-of-Bounds Read Vulnerability in YARA 3.5.0

Heap-based Out-of-Bounds Read Vulnerability in YARA 3.5.0

CVE-2017-5923 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:N/A:P

libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted rule that is mishandled in the yara_yyparse function.

Learn more about our Web Application Penetration Testing UK.