A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, can cause a crash and cause denial-of-service with a specially crafted Gerber RS-274X file.
References
| Link | Resource |
|---|---|
| https://github.com/gerbv/gerbv/commit/dfb5aac533a3f9e8ccd93ca217a753258cba4fe5 | Patch |
| https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4508 | Third Party Advisory |
| https://github.com/gerbv/gerbv/issues/191 | Exploit Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2023-08-24 23:15
Updated : 2023-08-29 17:49
NVD link : CVE-2023-4508
Mitre link : CVE-2023-4508
JSON object : View
Products Affected
gerbv_project
- gerbv
CWE
CWE-824
Access of Uninitialized Pointer
