CVE-2019-5020: Medium severity virustotal vulnerability
Published Jul 31, 2019
·Updated
An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file can cause a negative value to be read to satisfy an assert, resulting in Denial of Service. An attacker can create a malicious binary to trigger this vulnerability.
Affected Software
1 affected component
VirusTotal yara=3.8.1
Event History
Jul 31, 2019
CVE Published
via MITRE·04:38 PM
Data Sourced
via MITRE·04:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-5020?
CVE-2019-5020 is classified as a denial of service vulnerability.
2
How do I fix CVE-2019-5020?
To fix CVE-2019-5020, update Yara to the latest version that addresses the vulnerability.
3
What versions are affected by CVE-2019-5020?
CVE-2019-5020 affects Yara version 3.8.1.
4
Can CVE-2019-5020 be exploited remotely?
Yes, CVE-2019-5020 can be exploited remotely by supplying a specially crafted binary file.
5
What kind of attack does CVE-2019-5020 enable?
CVE-2019-5020 enables an attacker to cause a denial of service condition in Yara.