CVE-2021-40403: Medium severity gerbv vulnerability
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-40403?
CVE-2021-40403 is classified as an information disclosure vulnerability.
How do I fix CVE-2021-40403?
To fix CVE-2021-40403, upgrade Gerbv to version 2.8.0 or later.
Which versions of Gerbv are affected by CVE-2021-40403?
CVE-2021-40403 affects Gerbv versions 2.7.0 and 2.8.0 (forked dev version).
What can an attacker do with CVE-2021-40403?
An attacker can exploit CVE-2021-40403 to leak sensitive memory contents through specially-crafted pick-and-place files.
Is CVE-2021-40403 relevant for Fedora users?
Yes, CVE-2021-40403 can affect users running specific versions of Fedora that use the vulnerable Gerbv package.