PT-2022-1780 · Gerbv+4 · Gerbv+4

Claudio Bozzato

·

Published

2022-03-01

·

Updated

2024-12-25

·

CVE-2021-40400

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Gerbv versions 2.7.0 and dev (commit b5f1eacd) Gerbv forked version (commit d7f42a9a)
Description An out-of-bounds read issue exists in the RS-274X aperture macro outline primitive functionality. This can be triggered by a specially-crafted Gerber file, potentially leading to information disclosure. An attacker can exploit this by providing a malicious file.
Recommendations For Gerbv version 2.7.0, consider disabling the RS-274X aperture macro outline primitive functionality until a patch is available. For Gerbv dev (commit b5f1eacd), restrict access to the functionality that handles Gerber files to minimize the risk of exploitation. For the Gerbv forked version (commit d7f42a9a), avoid using the affected functionality with untrusted files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2024-17464
ALT-PU-2024-17535
BDU:2022-01143
CVE-2021-40400
MGASA-2022-0260
OPENSUSE-SU-2024:12527-1
USN-6209-1

Affected Products

Alt Linux
Debian
Gerbv
Linuxmint
Ubuntu