CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
AI Score
Confidence
Low
EPSS
Percentile
19.6%
George-Andrei Iosif and David Fernandez Gonzalez discovered that Gerbv did
not properly initialize a data structure when parsing certain nested
RS-274X format files. If a user were tricked into opening a specially
crafted file, an attacker could possibly use this issue to cause a denial
of service (application crash).
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Ubuntu | 23.10 | noarch | gerbv | < 2.9.8-1ubuntu0.1 | UNKNOWN |
Ubuntu | 23.10 | noarch | gerbv-dbgsym | < 2.9.8-1ubuntu0.1 | UNKNOWN |
Ubuntu | 22.04 | noarch | gerbv | < 2.8.2-1ubuntu0.1~esm2 | UNKNOWN |
Ubuntu | 22.04 | noarch | gerbv | < 2.8.2-1 | UNKNOWN |
Ubuntu | 22.04 | noarch | gerbv-dbgsym | < 2.8.2-1 | UNKNOWN |
Ubuntu | 20.04 | noarch | gerbv | < 2.7.0-1ubuntu0.2 | UNKNOWN |
Ubuntu | 20.04 | noarch | gerbv-dbgsym | < 2.7.0-1ubuntu0.2 | UNKNOWN |
Ubuntu | 18.04 | noarch | gerbv | < 2.6.1-3ubuntu0.1~esm2 | UNKNOWN |
Ubuntu | 18.04 | noarch | gerbv | < 2.6.1-3 | UNKNOWN |
Ubuntu | 18.04 | noarch | gerbv-dbgsym | < 2.6.1-3 | UNKNOWN |