CVE-2017-5924 is a use-after-free vulnerability in YARA 3.5.0, specifically within the libyara/grammar.y component, affecting products like VirusTotal YARA. This high-severity flaw (CVSS 7.5) allows remote attackers to trigger a denial of service and application crash via a crafted rule, requiring no user interaction or privileges. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.5.0CPE matchmatch criteria | cpe:2.3:a:virustotal:yara:3.5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.