CVE-2018-19974: Medium severity virustotal vulnerability
Published Dec 17, 2018
·Updated
In YARA 3.8.1, bytecode in a specially crafted compiled rule can read uninitialized data from VM scratch memory in libyara/exec.c. This can allow attackers to discover addresses in the real stack (not the YARA virtual stack).
Affected Software
1 affected component
VirusTotal yara=3.8.1
Event History
Dec 17, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19974?
CVE-2018-19974 is considered a moderate severity vulnerability due to potential information disclosure.
2
How do I fix CVE-2018-19974?
To mitigate CVE-2018-19974, upgrade YARA to version 3.8.2 or later.
3
What software is affected by CVE-2018-19974?
CVE-2018-19974 affects YARA version 3.8.1.
4
What type of attack can CVE-2018-19974 facilitate?
CVE-2018-19974 can facilitate information disclosure by allowing attackers to read uninitialized data.
5
What does CVE-2018-19974 exploit in YARA?
CVE-2018-19974 exploits the ability of specially crafted bytecode to access VM scratch memory.