CVE-2017-9465 describes a buffer over-read vulnerability in YARA 3.6.1, specifically within the yr_arena_write_data function, affecting products like virustotal yara. This flaw can be triggered by a crafted file, leading to a denial of service (application crash) or potential information disclosure from process memory. With a CVSS score of 7.1 (High), it requires user interaction and local access to exploit, but can result in high confidentiality and availability impacts. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed on the KEV catalog, and it shows minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.6.1CPE matchmatch criteria | cpe:2.3:a:virustotal:yara:3.6.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.