CVE-2021-40401: Use After Free
A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-40401?
CVE-2021-40401 is considered to have a high severity due to its potential for code execution through specially crafted Gerber files.
How do I fix CVE-2021-40401?
To fix CVE-2021-40401, upgrade to versions 2.7.1-forked_dev or later for Gerbv.
Which software versions are affected by CVE-2021-40401?
CVE-2021-40401 affects Gerbv versions up to and including 2.7.0 and the forked version 2.7.1.
Can CVE-2021-40401 be exploited remotely?
Yes, CVE-2021-40401 can be exploited remotely if an attacker provides a malicious Gerber file.
What kind of attack is CVE-2021-40401 associated with?
CVE-2021-40401 is associated with a use-after-free vulnerability leading to potential code execution.