PT-2021-22891 · Gerbv+3 · Gerbv+3

Claudio Bozzato

·

Published

2021-11-19

·

Updated

2024-12-25

·

CVE-2021-40391

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gerbv version 2.7.0 Gerbv dev (commit b5f1eacd) Gerbv forked version (commit 71493260)
Description An out-of-bounds write issue exists in the drill format T-code tool number functionality. A specially-crafted drill file can lead to code execution. An attacker can provide a malicious file to trigger this issue.
Recommendations For Gerbv version 2.7.0, consider disabling the drill format T-code tool number functionality until a patch is available. For Gerbv dev (commit b5f1eacd), restrict access to the drill file processing module to minimize the risk of exploitation. For Gerbv forked version (commit 71493260), avoid using the vulnerable drill file functionality until the issue is resolved. As a temporary workaround, consider validating all drill files before processing them to prevent malicious files from being executed.

Exploit

Fix

Memory Corruption

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

ALT-PU-2024-17464
ALT-PU-2024-17535
CVE-2021-40391
DLA-2839-1
MGASA-2022-0260
OPENSUSE-SU-2024:12064-1
USN-6209-1

Affected Products

Alt Linux
Gerbv
Linuxmint
Ubuntu