Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-11187
HistoryFeb 16, 2022 - 12:00 a.m.

KiCad buffer overflow vulnerability

2022-02-1600:00:00
China National Vulnerability Database
www.cnvd.org.cn
17
kicad eda
buffer overflow
gcodenumber parsing
vulnerability
gerber
excellon
code execution
security

EPSS

0.003

Percentile

69.6%

Kicad is a free software for printed circuit board design from the KiCad Eda community. A security vulnerability exists in KiCad EDA, which stems from a stack buffer overflow vulnerability in the Viewer gerber and excellon GCodeNumber parsing functions in KiCad EDA 6.0.1 and master branches. An attacker could exploit the vulnerability via a specially crafted gerber or excellon file that could lead to code execution.