Vulnerability Description
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gerbv Project | Gerbv | 2.7.0 |
| Fedoraproject | Fedora | 36 |
| Debian | Debian Linux | 11.0 |
Related Weaknesses (CWE)
References
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://talosintelligence.com/vulnerability_reports/TALOS-2021-1417ExploitThird Party Advisory
- https://www.debian.org/security/2022/dsa-5306Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://talosintelligence.com/vulnerability_reports/TALOS-2021-1417ExploitThird Party Advisory
- https://www.debian.org/security/2022/dsa-5306Third Party Advisory
FAQ
What is CVE-2021-40403?
CVE-2021-40403 is a vulnerability with a CVSS score of 6.3 (MEDIUM). An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place...
How severe is CVE-2021-40403?
CVE-2021-40403 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-40403?
Check the references section above for vendor advisories and patch information. Affected products include: Gerbv Project Gerbv, Fedoraproject Fedora, Debian Debian Linux.