Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-40857

Опубликовано: 29 авг. 2023
Источник: redhat
CVSS3: 8.8

Описание

Buffer Overflow vulnerability in VirusTotal yara v.4.3.2 allows a remote attacker to execute arbtirary code via the yr_execute_cod function in the exe.c component.

A flaw was found in the yara library. This issue occurs due to a buffer overflow vulnerability in the exe.c component that allows a remote attacker to execute arbtirary code via the yr_execute_cod function.

Отчет

The Insights Malware app only supports running the rules file we provide to the customer. We ensure the rules file we provide runs without failure by yara is not corrupted. We can't do much about customers choosing to run their own rules files and crashing yara if the rules file they provide is corrupt. That is not supported by the malware app.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8yaraNot affected
Red Hat Enterprise Linux 9yaraNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2235688yara: buffer overflow that allows a remote attacker to execute arbtirary code via the yr_execute_cod function

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 2 лет назад

Buffer Overflow vulnerability in VirusTotal yara v.4.3.2 allows a remote attacker to execute arbtirary code via the yr_execute_cod function in the exe.c component.

CVSS3: 8.8
nvd
больше 2 лет назад

Buffer Overflow vulnerability in VirusTotal yara v.4.3.2 allows a remote attacker to execute arbtirary code via the yr_execute_cod function in the exe.c component.

CVSS3: 8.8
debian
больше 2 лет назад

Buffer Overflow vulnerability in VirusTotal yara v.4.3.2 allows a remo ...

CVSS3: 8.8
github
больше 2 лет назад

Buffer Overflow vulnerability in VirusTotal yara v.4.3.2 allows a remote attacker to execute arbtirary code via the yr_execute_cod function in the exe.c component.

8.8 High

CVSS3