Lucene search

K
osvGoogleOSV:CVE-2021-40401
HistoryFeb 04, 2022 - 11:15 p.m.

CVE-2021-40401

2022-02-0423:15:11
Google
osv.dev
6
use-after-free
vulnerability
gerbv 2.7.0
gerbv 2.7.1
code execution
gerber file
malicious file

AI Score

7

Confidence

Low

EPSS

0.004

Percentile

72.7%

A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

AI Score

7

Confidence

Low

EPSS

0.004

Percentile

72.7%