CVE-2021-40394: Critical severity gerbv vulnerability
An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-40394?
CVE-2021-40394 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2021-40394?
To fix CVE-2021-40394, update Gerbv to version 2.7.0-2 or later for Debian systems.
What are the affected software versions for CVE-2021-40394?
The affected software versions for CVE-2021-40394 include Gerbv versions up to 2.7.0-1+deb10u1.
Can CVE-2021-40394 lead to code execution?
Yes, CVE-2021-40394 can lead to arbitrary code execution when a malicious gerber file is processed.
Is CVE-2021-40394 present in all versions of Gerbv?
No, CVE-2021-40394 is specific to Gerbv versions 2.7.0 and certain forked versions.