PT-2021-22891 · Gerbv+3 · Gerbv+3
Claudio Bozzato
·
Published
2021-11-19
·
Updated
2024-12-25
·
CVE-2021-40391
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gerbv version 2.7.0
Gerbv dev (commit b5f1eacd)
Gerbv forked version (commit 71493260)
Description
An out-of-bounds write issue exists in the drill format T-code tool number functionality. A specially-crafted drill file can lead to code execution. An attacker can provide a malicious file to trigger this issue.
Recommendations
For Gerbv version 2.7.0, consider disabling the drill format T-code tool number functionality until a patch is available.
For Gerbv dev (commit b5f1eacd), restrict access to the drill file processing module to minimize the risk of exploitation.
For Gerbv forked version (commit 71493260), avoid using the vulnerable drill file functionality until the issue is resolved.
As a temporary workaround, consider validating all drill files before processing them to prevent malicious files from being executed.
Exploit
Fix
Memory Corruption
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Gerbv
Linuxmint
Ubuntu