Debian Gerbv vulnerabilities

8 known vulnerabilities affecting debian/gerbv.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH1MEDIUM1LOW3

Vulnerabilities

Page 1 of 1
CVE-2023-4508LOWCVSS 5.5fixed in gerbv 2.10.0-1 (sid)2023
CVE-2023-4508 [MEDIUM] CVE-2023-4508: gerbv - A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, c... A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, can cause a crash and cause denial-of-service with a specially crafted Gerber RS-274X file. Scope: local bookworm: open bullseye: open sid: resolved (fixed in 2.10.0-1) trixie: resolved (fixed in 2.10.0-1)
debian
CVE-2021-40394CRITICALCVSS 9.8fixed in gerbv 2.8.1-1 (bookworm)2021
CVE-2021-40394 [CRITICAL] CVE-2021-40394: gerbv - An out-of-bounds write vulnerability exists in the RS-274X aperture macro variab... An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fi
debian
CVE-2021-40391CRITICALCVSS 9.8fixed in gerbv 2.7.1-1 (bookworm)2021
CVE-2021-40391 [CRITICAL] CVE-2021-40391: gerbv - An out-of-bounds write vulnerability exists in the drill format T-code tool numb... An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forked version of Gerbv (commit 71493260). A specially-crafted drill file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 2.7.1-
debian
CVE-2021-40393CRITICALCVSS 9.8fixed in gerbv 2.8.2-1 (bookworm)2021
CVE-2021-40393 [CRITICAL] CVE-2021-40393: gerbv - An out-of-bounds write vulnerability exists in the RS-274X aperture macro variab... An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fi
debian
CVE-2021-40401HIGHCVSS 8.6fixed in gerbv 2.9.2-1 (bookworm)2021
CVE-2021-40401 [HIGH] CVE-2021-40401: gerbv - A use-after-free vulnerability exists in the RS-274X aperture definition tokeniz... A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (fixed in 2.9.2-1) bullseye: resolved (fi
debian
CVE-2021-40403MEDIUMCVSS 6.3fixed in gerbv 2.9.2-1 (bookworm)2021
CVE-2021-40403 [MEDIUM] CVE-2021-40403: gerbv - An information disclosure vulnerability exists in the pick-and-place rotation pa... An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerability. Scope: loca
debian
CVE-2021-40402LOWCVSS 7.52021
CVE-2021-40402 [HIGH] CVE-2021-40402: gerbv - An out-of-bounds read vulnerability exists in the RS-274X aperture macro multipl... An out-of-bounds read vulnerability exists in the RS-274X aperture macro multiple outline primitives functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.7.1 and 2.8.0. A specially-crafted Gerber file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability. Scope: local bookworm: open bullseye: o
debian
CVE-2021-40400LOWCVSS 7.5fixed in gerbv 2.9.2-1 (bookworm)2021
CVE-2021-40400 [HIGH] CVE-2021-40400: gerbv - An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline... An out-of-bounds read vulnerability exists in the RS-274X aperture macro outline primitive functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit d7f42a9a). A specially-crafted Gerber file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability. Scope: local bookworm: resolved (
debian