CVE-2021-40400
published 2022-04-14CVE-2021-40400: An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.27%
66.5th percentile
An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit d7f42a9a). A specially-crafted Gerber file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gerbv | < gerbv 2.9.2-1 (bookworm) | gerbv 2.9.2-1 (bookworm) |
| gerbv | gerbv | — | — |
| gerbv | gerbv | — | — |
| gerbv | gerbv_forked | — | — |
| gerbv_project | gerbv | — | — |
| gerbv_project | gerbv | >= 0 < 2.9.2-1 | 2.9.2-1 |
| gerbv_project | gerbv | >= 0 < 2.9.2-1 | 2.9.2-1 |
| gerbv_project | gerbv | >= 0 < 2.7.0-1ubuntu0.1 | 2.7.0-1ubuntu0.1 |
| gerbv_project | gerbv | >= 0 < 2.6.0-1ubuntu0.14.04.1~esm1 | 2.6.0-1ubuntu0.14.04.1~esm1 |
| gerbv_project | gerbv | >= 0 < 2.6.0-1ubuntu0.16.04.1~esm1 | 2.6.0-1ubuntu0.16.04.1~esm1 |
| gerbv_project | gerbv | >= 0 < 2.6.1-3ubuntu0.1~esm1 | 2.6.1-3ubuntu0.1~esm1 |
| gerbv_project | gerbv | >= 0 < 2.8.2-1ubuntu0.1~esm1 | 2.8.2-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.09.3CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Gerbv vulnerabilities
osv·2023-07-07·CVSS 9.8
CVE-2021-40391 [CRITICAL] Gerbv vulnerabilities
Gerbv vulnerabilities
Claudio Bozzato discovered that Gerbv incorrectly handled certain Gerber
files. An attacker could possibly use this issue to crash Gerbv (resulting
in a denial of service), or execute arbitrary code. This issue only
affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
20.04 LTS. (CVE-2021-40391, CVE-2021-40394)
Claudio Bozzato discovered that Gerbv incorrectly handled certain Gerber
files. An attacker could possibly use this issue to disclose information,
crash Gerbv (resulting in a denial of service), or execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 20.04 LTS. (CVE-2021-40393)
Claudio Bozzato discovered that Gerbv incorrectly handled certain Gerber
files. An attacker could pos
GHSA
GHSA-6c2w-p226-q9q8: An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2
ghsa_unreviewed·2022-04-15
CVE-2021-40400 [HIGH] CWE-125 GHSA-6c2w-p226-q9q8: An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2
An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit d7f42a9a). A specially-crafted Gerber file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.
OSV
CVE-2021-40400: An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2
osv·2022-04-14·CVSS 7.5
CVE-2021-40400 [HIGH] CVE-2021-40400: An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2
An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit d7f42a9a). A specially-crafted Gerber file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.
Debian
CVE-2021-40400: gerbv - An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline...
vendor_debian·2021·CVSS 7.5
CVE-2021-40400 [HIGH] CVE-2021-40400: gerbv - An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline...
An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit d7f42a9a). A specially-crafted Gerber file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.9.2-1)
bullseye: open
sid: resolved (fixed in 2.9.2-1)
trixie: resolved (fixed in 2.9.2-1)
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Vulnerabilities in Gerbv could lead to code execution, information disclosure
blogs_talos·2022-02-24·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Vulnerabilities in Gerbv could lead to code execution, information disclosure
## Vulnerability Spotlight: Vulnerabilities in Gerbv could lead to code execution, information disclosure
Claudio Bozzato of Cisco Talos discovered these vulnerabilities.
Cisco Talos recently discovered multiple vulnerabilities in the Gerbv file viewing software that could allow an attacker to execute arbitrary remote code or disclose sensitive information.
Gerbv is an open-source software that allows users to view RS-274X Gerber files, Excellon drill files and pick-n-place files — all common file formats used to display layers of a circuit board and other computer parts. All of these vulnerabilities exist in the function that allows Gerbv to open Gerber files. Gerbv can be used as a standalone GUI application, or as a library.
TALOS-2021-1402 (CVE-2021-40391), TALOS-2021-1404 (CVE-202
Talos
Vulnerability Spotlight: Vulnerabilities in Gerbv could lead to code execution, information disclosure
blogs_talos·2022-02-24·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Vulnerabilities in Gerbv could lead to code execution, information disclosure
Claudio Bozzato of Cisco Talos discovered these vulnerabilities.
Cisco Talos recently discovered multiple vulnerabilities in the Gerbv file viewing software that could allow an attacker to execute arbitrary remote code or disclose sensitive information.
Gerbv is an open-source software that allows users to view RS-274X Gerber files, Excellon drill files and pick-n-place files — all common file formats used to display layers of a circuit board and other computer parts. All of these vulnerabilities exist in the function that allows Gerbv to open Gerber files. Gerbv can be used as a standalone GUI application, or as a library.
TALOS-2021-1402 (CVE-2021-40391), TALOS-2021-1404 (CVE-2021-40393), TALOS-2021-1405 (CVE-2021-40394) and TALOS-2021-1415 (CVE-2021-40401) could all be triggered if a
2022-04-14
Published