CVE-2021-40403
published 2022-02-04CVE-2021-40403: An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked…
PriorityP426medium6.3CVSS 3.1
AVLACLPRNUIRSCCHINAN
EPSS
1.08%
61.8th percentile
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerability.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | gerbv | < gerbv 2.9.2-1 (bookworm) | gerbv 2.9.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| gerbv_project | gerbv | — | — |
| gerbv_project | gerbv | — | — |
| gerbv_project | gerbv | — | — |
| gerbv_project | gerbv | >= 0 < 2.7.0-2+deb11u2 | 2.7.0-2+deb11u2 |
| gerbv_project | gerbv | >= 0 < 2.9.2-1 | 2.9.2-1 |
| gerbv_project | gerbv | >= 0 < 2.9.2-1 | 2.9.2-1 |
| gerbv_project | gerbv | >= 0 < 2.7.0-1ubuntu0.1 | 2.7.0-1ubuntu0.1 |
| gerbv_project | gerbv | >= 0 < 2.6.0-1ubuntu0.14.04.1~esm1 | 2.6.0-1ubuntu0.14.04.1~esm1 |
| gerbv_project | gerbv | >= 0 < 2.6.0-1ubuntu0.16.04.1~esm1 | 2.6.0-1ubuntu0.16.04.1~esm1 |
| gerbv_project | gerbv | >= 0 < 2.6.1-3ubuntu0.1~esm1 | 2.6.1-3ubuntu0.1~esm1 |
| gerbv_project | gerbv | >= 0 < 2.8.2-1ubuntu0.1~esm1 | 2.8.2-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
nvdv3.05.8MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_debian6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2021-40403: gerbv - An information disclosure vulnerability exists in the pick-and-place rotation pa...
vendor_debian·2021·CVSS 6.3
CVE-2021-40403 [MEDIUM] CVE-2021-40403: gerbv - An information disclosure vulnerability exists in the pick-and-place rotation pa...
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.9.2-1)
bullseye: resolved (fixed in 2.7.0-2+deb11u2)
sid: resolved (fixed in 2.9.2-1)
trixie: resolved (fixed in 2.9.2-1)
OSV
Gerbv vulnerabilities
osv·2023-07-07·CVSS 9.8
CVE-2021-40391 [CRITICAL] Gerbv vulnerabilities
Gerbv vulnerabilities
Claudio Bozzato discovered that Gerbv incorrectly handled certain Gerber
files. An attacker could possibly use this issue to crash Gerbv (resulting
in a denial of service), or execute arbitrary code. This issue only
affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
20.04 LTS. (CVE-2021-40391, CVE-2021-40394)
Claudio Bozzato discovered that Gerbv incorrectly handled certain Gerber
files. An attacker could possibly use this issue to disclose information,
crash Gerbv (resulting in a denial of service), or execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 20.04 LTS. (CVE-2021-40393)
Claudio Bozzato discovered that Gerbv incorrectly handled certain Gerber
files. An attacker could pos
GHSA
GHSA-hmq5-vc89-4m9m: An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2
ghsa_unreviewed·2022-02-10
CVE-2021-40403 [MEDIUM] CWE-456 GHSA-hmq5-vc89-4m9m: An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerability.
OSV
CVE-2021-40403: An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2
osv·2022-02-04·CVSS 6.3
CVE-2021-40403 [MEDIUM] CVE-2021-40403: An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerability.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Vulnerabilities in Gerbv could lead to code execution, information disclosure
blogs_talos·2022-02-24·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Vulnerabilities in Gerbv could lead to code execution, information disclosure
## Vulnerability Spotlight: Vulnerabilities in Gerbv could lead to code execution, information disclosure
Claudio Bozzato of Cisco Talos discovered these vulnerabilities.
Cisco Talos recently discovered multiple vulnerabilities in the Gerbv file viewing software that could allow an attacker to execute arbitrary remote code or disclose sensitive information.
Gerbv is an open-source software that allows users to view RS-274X Gerber files, Excellon drill files and pick-n-place files — all common file formats used to display layers of a circuit board and other computer parts. All of these vulnerabilities exist in the function that allows Gerbv to open Gerber files. Gerbv can be used as a standalone GUI application, or as a library.
TALOS-2021-1402 (CVE-2021-40391), TALOS-2021-1404 (CVE-202
Talos
Vulnerability Spotlight: Vulnerabilities in Gerbv could lead to code execution, information disclosure
blogs_talos·2022-02-24·CVSS 9.8
[CRITICAL] Vulnerability Spotlight: Vulnerabilities in Gerbv could lead to code execution, information disclosure
Claudio Bozzato of Cisco Talos discovered these vulnerabilities.
Cisco Talos recently discovered multiple vulnerabilities in the Gerbv file viewing software that could allow an attacker to execute arbitrary remote code or disclose sensitive information.
Gerbv is an open-source software that allows users to view RS-274X Gerber files, Excellon drill files and pick-n-place files — all common file formats used to display layers of a circuit board and other computer parts. All of these vulnerabilities exist in the function that allows Gerbv to open Gerber files. Gerbv can be used as a standalone GUI application, or as a library.
TALOS-2021-1402 (CVE-2021-40391), TALOS-2021-1404 (CVE-2021-40393), TALOS-2021-1405 (CVE-2021-40394) and TALOS-2021-1415 (CVE-2021-40401) could all be triggered if a
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PTGBC37N2FV7NKOWFVCFMPAFYEPHSB7C/https://talosintelligence.com/vulnerability_reports/TALOS-2021-1417https://www.debian.org/security/2022/dsa-5306https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PTGBC37N2FV7NKOWFVCFMPAFYEPHSB7C/https://talosintelligence.com/vulnerability_reports/TALOS-2021-1417https://www.debian.org/security/2022/dsa-5306
2022-02-04
Published