libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule (involving hex strings) that is mishandled in the _yr_re_emit function, a different vulnerability than CVE-2017-9304.
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Yara | Virustotal | 3.5.0 (including) | 3.5.0 (including) |
Yara | Ubuntu | artful | * |
Yara | Ubuntu | esm-apps/xenial | * |
Yara | Ubuntu | trusty | * |
Yara | Ubuntu | upstream | * |
Yara | Ubuntu | xenial | * |
Yara | Ubuntu | yakkety | * |
Yara | Ubuntu | zesty | * |