Bugzilla – Bug 1214753
VUL-0: CVE-2023-40857: yara: Buffer Overflow
Last modified: 2023-09-11 11:42:36 UTC
CVE-2023-40857 Buffer Overflow vulnerability in VirusTotal yara v.4.3.2 allows a remote attacker to execute arbtirary code via the yr_execute_cod function in the exe.c component. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-40857 https://bugzilla.redhat.com/show_bug.cgi?id=2235688 https://www.cve.org/CVERecord?id=CVE-2023-40857 https://github.com/VirusTotal/yara/issues/1945
This CVE has been disputed. see https://github.com/VirusTotal/yara/issues/1948#issuecomment-1672869957 can we close this?