Lucene search

K
cvelistTalosCVELIST:CVE-2021-40402
HistoryApr 14, 2022 - 7:56 p.m.

CVE-2021-40402

2022-04-1419:56:14
CWE-755
talos
www.cve.org
4
rs-274x aperture macro
information disclosure
gerber file
malicious file
vulnerability

CVSS3

9.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:H

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

59.0%

An out-of-bounds read vulnerability exists in the RS-274X aperture macro multiple outline primitives functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.7.1 and 2.8.0. A specially-crafted Gerber file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

CNA Affected

[
  {
    "product": "Gerbv",
    "vendor": "Gerbv",
    "versions": [
      {
        "status": "affected",
        "version": "2.7.0"
      },
      {
        "status": "affected",
        "version": "dev  (commit b5f1eacd)"
      }
    ]
  },
  {
    "product": "Gerbv forked",
    "vendor": "Gerbv",
    "versions": [
      {
        "status": "affected",
        "version": "2.7.1"
      },
      {
        "status": "affected",
        "version": "2.8.0"
      }
    ]
  }
]

CVSS3

9.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:H

AI Score

7.5

Confidence

High

EPSS

0.002

Percentile

59.0%

Related for CVELIST:CVE-2021-40402