CVE-2023-4508
published 2023-08-24CVE-2023-4508: A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, can cause a crash and cause denial-of-service with a specially crafted Gerber…
PriorityP417medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.31%
23.1th percentile
A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, can cause a crash and cause denial-of-service with a specially crafted Gerber RS-274X file.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gerbv | < gerbv 2.10.0-1 (sid) | gerbv 2.10.0-1 (sid) |
| gerbv | gerbv | >= 2.4.0 < 2.10.0 | 2.10.0 |
| gerbv_project | gerbv | >= 0 < 2.10.0-1 | 2.10.0-1 |
| gerbv_project | gerbv | 2.4.0 – 2.10.0 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m4qj-9cr4-hrw4: A user able to control file input to Gerbv, between versions 2
ghsa_unreviewed·2023-08-25
CVE-2023-4508 [MEDIUM] CWE-824 GHSA-m4qj-9cr4-hrw4: A user able to control file input to Gerbv, between versions 2
A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, can cause a crash and cause denial-of-service with a specially crafted Gerber RS-274X file.
OSV
CVE-2023-4508: A user able to control file input to Gerbv, between versions 2
osv·2023-08-24·CVSS 5.5
CVE-2023-4508 [MEDIUM] CVE-2023-4508: A user able to control file input to Gerbv, between versions 2
A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, can cause a crash and cause denial-of-service with a specially crafted Gerber RS-274X file.
Ubuntu
Gerbv vulnerability
vendor_ubuntu·2024-04-30
CVE-2023-4508 Gerbv vulnerability
Title: Gerbv vulnerability
Summary: Gerbv could be made to crash if it opened a specially crafted input file.
George-Andrei Iosif and David Fernandez Gonzalez discovered that Gerbv did
not properly initialize a data structure when parsing certain nested
RS-274X format files. If a user were tricked into opening a specially
crafted file, an attacker could possibly use this issue to cause a denial
of service (application crash).
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2023-4508: gerbv - A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, c...
vendor_debian·2023·CVSS 5.5
CVE-2023-4508 [MEDIUM] CVE-2023-4508: gerbv - A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, c...
A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, can cause a crash and cause denial-of-service with a specially crafted Gerber RS-274X file.
Scope: local
bookworm: open
bullseye: open
sid: resolved (fixed in 2.10.0-1)
trixie: resolved (fixed in 2.10.0-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4508https://github.com/gerbv/gerbv/commit/5517e22250e935dc7f86f64ad414aeae3dbcb36ahttps://github.com/gerbv/gerbv/issues/191https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4508https://github.com/gerbv/gerbv/commit/5517e22250e935dc7f86f64ad414aeae3dbcb36ahttps://github.com/gerbv/gerbv/issues/191
2023-08-24
Published