CVE-2023-4508: Denial of Service in Gerbv
Published Aug 24, 2023
·Updated
A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, can cause a crash and cause denial-of-service with a specially crafted Gerber RS-274X file.
Affected Software
8 affected componentsFixes available
debian/gerbv<=2.7.0-1+deb10u1, <=2.7.0-2+deb11u2, <=2.9.6-1
2.7.0-1+deb10u32.10.0-1
ubuntu/gerbv<2.6.1-3ubuntu0.1~
2.6.1-3ubuntu0.1~
ubuntu/gerbv<2.7.0-1ubuntu0.2
2.7.0-1ubuntu0.2
ubuntu/gerbv<2.8.2-1ubuntu0.1~
2.8.2-1ubuntu0.1~
ubuntu/gerbv<2.9.8-1ubuntu0.1
2.9.8-1ubuntu0.1
ubuntu/gerbv<2.10.0
2.10.0
ubuntu/gerbv<2.6.0-1ubuntu0.16.04.1~
2.6.0-1ubuntu0.16.04.1~
Gerbv Project Gerbv>=2.4.0<=2.10.0
Remediation
Event History
Aug 24, 2023
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·10:51 PM
Data Sourced
via MITRE·10:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
May 4, 2024
Data Sourced
via Launchpad·11:57 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-4508?
CVE-2023-4508 is classified as a denial-of-service vulnerability due to potential crashes caused by specially crafted Gerber RS-274X files.
2
How do I fix CVE-2023-4508?
To fix CVE-2023-4508, upgrade Gerbv to version 2.10.0 or later or to any patched version as specified by your distribution.
3
Which versions of Gerbv are affected by CVE-2023-4508?
Gerbv versions from 2.4.0 up to and including 2.10.0 are affected by CVE-2023-4508.
4
What impact can CVE-2023-4508 have on affected systems?
CVE-2023-4508 can cause a denial-of-service, resulting in application crashes when processing malicious files.
5
Is there a exploit for CVE-2023-4508 in the wild?
As of now, there have been no publicly reported exploits for CVE-2023-4508.