CVE-2019-19648: High severity virustotal vulnerability
Published Dec 9, 2019
·Updated
In the machoparsefile functionality in macho/macho.c of YARA 3.11.0, commandsize may be inconsistent with the real size. A specially crafted MachO file can cause an out-of-bounds memory access, resulting in Denial of Service (application crash) or potential code execution.
Affected Software
3 affected components
VirusTotal yara=3.11.0
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Event History
Dec 9, 2019
CVE Published
via MITRE·12:37 AM
Data Sourced
via MITRE·12:37 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-19648?
CVE-2019-19648 has a severity rating that indicates a risk of Denial of Service or potential code execution.
2
How can I fix CVE-2019-19648?
To fix CVE-2019-19648, upgrade YARA to the latest version that addresses this vulnerability.
3
Which versions of YARA are affected by CVE-2019-19648?
CVE-2019-19648 affects YARA version 3.11.0.
4
Does CVE-2019-19648 affect Fedora operating systems?
Yes, CVE-2019-19648 is relevant to Fedora versions 33 and 34.
5
What happens if I encounter CVE-2019-19648?
Encountering CVE-2019-19648 can lead to application crashes or exploit opportunities through out-of-bounds memory access.