UBUNTU-CVE-2021-40391
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-40391
UBUNTU-CVE-2021-40391
Summary:
Details: An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forked version of Gerbv (commit 71493260). A specially-crafted drill file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
References: https://ubuntu.com/security/CVE-2021-40391, https://talosintelligence.com/vulnerability_reports/TALOS-2021-1402, https://github.com/gerbv/gerbv/commit/9f83950b772b37b49ee188300e444546e6aab17e, https://github.com/gerbv/gerbv/issues/30, https://ubuntu.com/security/notices/USN-6209-1, https://www.cve.org/CVERecord?id=CVE-2021-40391
Affected packages
Package
Name: gerbv
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
