CVE-2018-12034 (NVD)

2018-06-15

In YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds read vulnerability in yr_execute_code in libyara/exec.c.

Products Yara
Type Out-of-bounds Read (CWE-125)
First patch - None (likely due to unavailable code)
Links https://github.com/VirusTotal/yara/issues/891
https://bnbdr.github.io/posts/swisscheese/
https://github.com/bnbdr/swisscheese