Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Library yara has vulnerability CVE-2021-45429 #7861

Closed
github-actions bot opened this issue Dec 3, 2022 · 1 comment · Fixed by #7912
Closed

Library yara has vulnerability CVE-2021-45429 #7861

github-actions bot opened this issue Dec 3, 2022 · 1 comment · Fixed by #7912
Labels
cve libraries For things referring to osquery third party libraries security severity-medium

Comments

@github-actions
Copy link

github-actions bot commented Dec 3, 2022

https://nvd.nist.gov/vuln/detail/CVE-2021-45429

A Buffer Overflow vulnerablity exists in VirusTotal YARA git commit: 605b2edf07ed8eb9a2c61ba22eb2e7c362f47ba7 via yr_set_configuration in yara/libyara/libyara.c, which could cause a Denial of Service.

@github-actions github-actions bot added cve libraries For things referring to osquery third party libraries security severity-medium labels Dec 3, 2022
@Smjert
Copy link
Member

Smjert commented Dec 8, 2022

osquery might be affected by this issue but it would be really difficult to trigger due to the need of a second bug that permits to write on the stack in a very specific position.
It's suggested to update, but with low priority.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cve libraries For things referring to osquery third party libraries security severity-medium
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant