Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36123
HistoryJun 26, 2022 - 4:25 p.m.

Use After Free

2022-06-2616:25:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23
use-after-free
gerbv
2.7.0
2.7.1
rs-274x
aperture definition
tokenization functionality
code execution
gerber file
malicious file
vulnerability

EPSS

0.004

Percentile

72.7%

A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.