Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 8: MGASA-2022-0176 Moderate: Gerbv Information Disclosure

mageia
Calendar Grey May 12, 2022
Dist Mageia Esm H88
Essential upgrade for Gerbv 2.7.0 to address security threats associated with memory leaks. Updated details on vulnerability fixes available here.
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0

Summary

An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerability. (CVE-2021-40403)

References

- https://bugs.mageia.org/show_bug.cgi?id=30391

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/PTGBC37N2FV7NKOWFVCFMPAFYEPHSB7C/

- https://www.cve.org/CVERecord?id=CVE-2021-40403

Resolution

SRPMS

- 8/core/gerbv-2.7.0-3.1.mga8

Publication date: 12 May 2022
URL: https://advisories.mageia.org/MGASA-2022-0176.html
Type: security
CVE: CVE-2021-40403

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here