CVE-2017-9438 is a denial-of-service vulnerability affecting YARA 3.5.0, specifically within its regexp module (libyara/re.c). A remote attacker can trigger stack consumption by providing a specially crafted YARA rule containing hex strings, which is improperly handled by the _yr_re_emit function. This vulnerability carries a CVSSv3 score of 7.5 (High), indicating a network-based attack with low complexity that can lead to high availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.5.0CPE matchmatch criteria | cpe:2.3:a:virustotal:yara:3.5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.