CVE-2019-19648 is a high-severity vulnerability affecting YARA 3.11.0 and related Fedora/VirusTotal products. It stems from an out-of-bounds memory access within the macho_parse_file functionality when processing specially crafted MachO files. This can lead to a Denial of Service (application crash) or potentially arbitrary code execution. The vulnerability has a CVSS score of 7.8, indicating a high impact with local access and user interaction required. There is currently no known active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.11.0CPE matchmatch criteria | cpe:2.3:a:virustotal:yara:3.11.0:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.