CVE-2018-19975: High severity virustotal vulnerability
Published Dec 17, 2018
·Updated
In YARA 3.8.1, bytecode in a specially crafted compiled rule can read data from any arbitrary address in memory, in libyara/exec.c. Specifically, OPCOUNT can read a DWORD.
Affected Software
1 affected component
VirusTotal yara=3.8.1
Event History
Dec 17, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19975?
CVE-2018-19975 is classified as a medium severity vulnerability due to the potential for arbitrary memory reads.
2
How do I fix CVE-2018-19975?
To fix CVE-2018-19975, update YARA to version 3.8.2 or later, where the vulnerability is resolved.
3
What software is affected by CVE-2018-19975?
CVE-2018-19975 affects YARA version 3.8.1, specifically developed by VirusTotal.
4
What is the impact of CVE-2018-19975 on systems?
The impact of CVE-2018-19975 includes the ability for crafted rules to exploit the bytecode execution and potentially expose sensitive data.
5
Is CVE-2018-19975 exploitable in all environments?
CVE-2018-19975 may be exploitable in environments where YARA 3.8.1 is used to process untrusted input.