PT-2022-11231 · Gerbv+3 · Gerbv+3

Claudio Bozzato

·

Published

2022-02-04

·

Updated

2024-12-25

·

CVE-2021-40403

CVSS v3.1

6.3

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Gerbv versions 2.7.0 through 2.8.0 Gerbv dev (commit b5f1eacd)
Description An information disclosure issue exists in the pick-and-place rotation parsing functionality. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this issue.
Recommendations For Gerbv versions 2.7.0 through 2.8.0, consider avoiding the use of the pick-and-place rotation parsing functionality until a patch is available. For Gerbv dev (commit b5f1eacd), restrict the processing of pick-and-place files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

ALT-PU-2024-17464
ALT-PU-2024-17535
CVE-2021-40403
DLA-3210-1
DSA-5306-1
MGASA-2022-0176
OPENSUSE-SU-2024:12527-1
USN-6209-1

Affected Products

Alt Linux
Gerbv
Linuxmint
Ubuntu