Triage yara for Jessie.
Add link to fixing commit. The affected code is not present in Jessie. However features to mitigate maliciously compiled bytecode were introduced only in later versions. That means that this specific exploit might not work but there are certainly other ways to escape the virtual machine if someone crafts a specific rules file. It is not trivial to craft the file and to trick a security researcher into using it. Hence this is no-dsa for Jessie.
Loading
Please register or sign in to comment