CVE-2021-45429: Buffer Overflow
A Buffer Overflow vulnerablity exists in VirusTotal YARA git commit: 605b2edf07ed8eb9a2c61ba22eb2e7c362f47ba7 via yrsetconfiguration in yara/libyara/libyara.c, which could cause a Denial of Service.
Other sources
YARA is vulnerable to a denial of service, caused by a buffer overflow in yrsetconfiguration in yara/libyara/libyara.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-45429?
CVE-2021-45429 is rated as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2021-45429?
To fix CVE-2021-45429, update YARA to version 4.2.3-4 or 4.5.2-1 or any later versions.
Which software is affected by CVE-2021-45429?
CVE-2021-45429 affects VirusTotal YARA versions up to and including 4.1.3 and versions starting from 4.2.0.
What type of vulnerability is CVE-2021-45429?
CVE-2021-45429 is a buffer overflow vulnerability.
Can CVE-2021-45429 lead to data leaks?
CVE-2021-45429 does not explicitly indicate data leaks but can compromise service availability, resulting in denial of service.