Lucene search

K
cvelistTalosCVELIST:CVE-2021-40403
HistoryFeb 04, 2022 - 12:00 a.m.

CVE-2021-40403

2022-02-0400:00:00
CWE-456
talos
www.cve.org
4
information disclosure
gerbv
pick-and-place
rotation parsing
vulnerability
memory contents
malicious file

CVSS3

5.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

51.1%

An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerability.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Gerbv",
    "versions": [
      {
        "version": "Gerbv 2.7.0 ,Gerbv forked 2.8.0 ,Gerbv dev (commit b5f1eacd)",
        "status": "affected"
      }
    ]
  }
]

CVSS3

5.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

51.1%