YARA detection rule for CVE-2024-4367 arbitrary javascript execution in PDF.js# Detect CVE-2024-4367
Quick-and-dirty YARA detection rule for CVE-2024-4367 arbitrary javascript execution in PDF.js.
## Usage
```
$ yara expl_pdfjs_cve_2024_4367.yar poc_generalized_CVE-2024-4367.pdf
EXPL_PDFJS_CVE_2024_4367 poc_generalized_CVE-2024-4367.pdf
```
## Credits
POC and disclosure from https://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js/.
[4.0K] /data/pocs/e4daaaf51fda0cc67dcd37a7cbb99c867d671b5f
├── [ 464] expl_pdfjs_cve_2024_4367.yar
├── [1.0K] LICENSE
├── [ 20K] poc_generalized_CVE-2024-4367.pdf
└── [ 390] README.md
0 directories, 4 files