CVE-2021-3402: Integer Overflow
An integer overflow and several buffer overflow reads in libyara/modules/macho/macho.c in YARA v4.0.3 and earlier could allow an attacker to either cause denial of service or information disclosure via a malicious Mach-O file. Affects all versions before libyara 4.0.4
Other sources
Integer overflow in libyara/modules/macho/macho.c in yara v4.0.2 and earlier could allow an attacker to either cause denial of service or information disclosure via a malicious Mach-O file.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libyarato a version that resolves this vulnerability.Fixed in 4.0.4 - Upgrade
Upgrade
libyarato a version that resolves this vulnerability.Fixed in 4.0.4 - Upgrade
Upgrade
libyara/modules/macho/macho.c in YARA v4.0.3 and earlierto a version that resolves this vulnerability.Fixed in 4.0.4 - Upgrade
Upgrade
libyara/modules/macho/macho.c in yara v4.0.2 and earlierto a version that resolves this vulnerability.Fixed in 4.0.4
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3402?
CVE-2021-3402 is classified as a high severity vulnerability due to its potential for causing denial of service and information disclosure.
How do I fix CVE-2021-3402?
To fix CVE-2021-3402, upgrade to libyara version 4.0.4 or later.
What versions are affected by CVE-2021-3402?
CVE-2021-3402 affects all versions of libyara before 4.0.4.
What type of vulnerabilities are present in CVE-2021-3402?
CVE-2021-3402 contains an integer overflow and multiple buffer overflow reads.
What files or components are involved in CVE-2021-3402?
CVE-2021-3402 specifically involves the macho.c file within the libyara/modules/macho directory.