CVE-2017-9304 describes a denial-of-service vulnerability in YARA 3.5.0, specifically within the libyara/re.c regexp module, affecting products like VirusTotal YARA. An attacker can trigger stack consumption by providing a specially crafted rule to the _yr_re_emit function. This vulnerability carries a high CVSS score of 7.5, indicating a network-exploitable issue with low attack complexity and a high impact on availability, though it has no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.5.0CPE matchmatch criteria | cpe:2.3:a:virustotal:yara:3.5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.