Bugzilla – Bug 1195673
VUL-0: CVE-2021-40403: gerbv: pick-and-place rotation parsing use of uninitialized variable vulnerability
Last modified: 2022-02-08 11:15:02 UTC
rh#2051389 An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerability. https://talosintelligence.com/vulnerability_reports/TALOS-2021-1417 References: https://bugzilla.redhat.com/show_bug.cgi?id=2051389 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-40403 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40403 https://talosintelligence.com/vulnerability_reports/TALOS-2021-1417
Affected: - openSUSE:Backports:SLE-15-SP3 - openSUSE:Backports:SLE-15-SP4 - openSUSE:Factory Looks like this will be the fix, but it has not been merged yet: https://github.com/gerbv/gerbv/pull/85