PT-2023-27678 · Virustotal+1 · Yara+1

·

CVE-2023-40857

·

Published

2023-08-28

·

Updated

2023-09-21

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VirusTotal yara version 4.3.2
Description The issue allows a remote attacker to execute arbitrary code via the yr execute cod function in the exe.c component. This is a Buffer Overflow vulnerability.
Recommendations For VirusTotal yara version 4.3.2, as a temporary workaround, consider disabling the yr execute cod function until a patch is available. Restrict access to the exe.c component to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-5718
CVE-2023-40857

Affected Products

Alt Linux
Yara