Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora: 2022-4a3ef86baa Critical: Gerbv Out-Of-Bounds and Use-After-Free

fedora
Calendar Grey July 8, 2022
Dist Fedora Esm H88
Fedora Release: gerbv 2.9.2 fixes significant problems such as out-of-bounds and use-after-free vulnerabilities.
upstream release 2.9.2

Summary

Gerber Viewer (gerbv) is a viewer for Gerber files. Gerber files

are generated from PCB CAD system and sent to PCB manufacturers

as basis for the manufacturing process. The standard supported

by gerbv is RS-274X.

gerbv also supports drill files. The format supported are known

under names as NC-drill or Excellon. The format is a bit undefined

and different EDA-vendors implement it different.

gerbv is listed among Fedora Electronic Lab (FEL) packages.

upstream release 2.9.2

* Thu Jun 30 2022 Alain Vigne - 2.9.2-1

- new upstream release

[ 1 ] Bug #2041799 - CVE-2021-40391 gerbv: out-of-bounds write in the drill format T-code tool number functionality [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2041799

[ 2 ] Bug #2051387 - CVE-2021-40401 gerbv: A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=2051387

su -c 'dnf upgrade --advisory FEDORA-2022-4a3ef86baa' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 36
Version: 2.9.2
Release: 1.fc36
Summary: Gerber file viewer from the gEDA toolkit

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here