Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-5020

Опубликовано: 31 июл. 2019
Источник: debian

Описание

An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file can cause a negative value to be read to satisfy an assert, resulting in Denial of Service. An attacker can create a malicious binary to trigger this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
yarafixed3.9.0-1package
yaranot-affectedstretchpackage
yaranot-affectedjessiepackage

Примечания

  • https://talosintelligence.com/vulnerability_reports/TALOS-2019-0781

  • https://github.com/VirusTotal/yara/issues/1023

  • https://github.com/VirusTotal/yara/commit/1ecb0e66431bf5c5b4c2fdf622be969eb5f4a7cc

  • https://github.com/VirusTotal/yara/commit/a3784d3855029bd0ad24071e72746cc0c31b8cba

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 6 лет назад

An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file can cause a negative value to be read to satisfy an assert, resulting in Denial of Service. An attacker can create a malicious binary to trigger this vulnerability.

CVSS3: 5.5
nvd
больше 6 лет назад

An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file can cause a negative value to be read to satisfy an assert, resulting in Denial of Service. An attacker can create a malicious binary to trigger this vulnerability.

CVSS3: 5.5
github
больше 3 лет назад

An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file can cause a negative value to be read to satisfy an assert, resulting in Denial of Service. An attacker can create a malicious binary to trigger this vulnerability.