Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Library yara has vulnerability CVE-2021-45429 #8264

Open
github-actions bot opened this issue Feb 2, 2024 · 1 comment
Open

Library yara has vulnerability CVE-2021-45429 #8264

github-actions bot opened this issue Feb 2, 2024 · 1 comment
Labels
cve libraries For things referring to osquery third party libraries security severity-medium

Comments

@github-actions
Copy link

github-actions bot commented Feb 2, 2024

https://nvd.nist.gov/vuln/detail/CVE-2021-45429

A Buffer Overflow vulnerablity exists in VirusTotal YARA git commit: 605b2edf07ed8eb9a2c61ba22eb2e7c362f47ba7 via yr_set_configuration in yara/libyara/libyara.c, which could cause a Denial of Service.

@github-actions github-actions bot added cve libraries For things referring to osquery third party libraries security severity-medium labels Feb 2, 2024
@Smjert
Copy link
Member

Smjert commented Feb 23, 2024

I think this is an error in the NVD database. I can see that they are marking the affected versions from 4.2.0 up to 4.3.2, but the fix has been present since 4.2.0-rc1 (VirusTotal/yara@a36b497).

We also did already handle this in the past: #7861

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cve libraries For things referring to osquery third party libraries security severity-medium
Projects
None yet
Development

No branches or pull requests

1 participant