Denial of Service in YARA 3.5.0 via Crafted Rule in libyara/re.c

Denial of Service in YARA 3.5.0 via Crafted Rule in libyara/re.c

CVE-2017-8294 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:N/A:P

libyara/re.c in the regex component in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted rule that is mishandled in the yr_re_exec function.

Learn more about our Web Application Penetration Testing UK.