9.8
CVSSv3

CVE-2021-40393

Published: 22/12/2021 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gerbv project gerbv 2.7.0

debian debian linux 9.0

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Several vulnerabilities were discovered in gerbv, a Gerber file viewer, which could result in the execution of arbitrary code, denial of service or information disclosure if a specially crafted file is processed For the stable distribution (bullseye), these problems have been fixed in version 270-2+deb11u2 We recommend that you upgrade your ger ...
An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 281 A specially-crafted gerber file can lead to code execution An attacker can provide a malicious file to trigger this vulnerability ...