
CVE-2023-4508 – Denial of Service in Gerbv
https://notcve.org/view.php?id=CVE-2023-4508
24 Aug 2023 — A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, can cause a crash and cause denial-of-service with a specially crafted Gerber RS-274X file. George-Andrei Iosif and David Fernandez Gonzalez discovered that Gerbv did not properly initialize a data structure when parsing certain nested RS-274X format files. If a user were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. • https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4508 • CWE-824: Access of Uninitialized Pointer •

CVE-2021-40402
https://notcve.org/view.php?id=CVE-2021-40402
14 Apr 2022 — An out-of-bounds read vulnerability exists in the RS-274X aperture macro multiple outline primitives functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.7.1 and 2.8.0. A specially-crafted Gerber file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability. Se presenta una vulnerabilidad de lectura fuera de límites en la funcionalidad de primitivas de contorno múltiple de la macro RS-274X de Gerbv versiones 2.7.0 y dev (commit b5f1eacd... • https://talosintelligence.com/vulnerability_reports/TALOS-2021-1416 • CWE-125: Out-of-bounds Read CWE-755: Improper Handling of Exceptional Conditions •

CVE-2021-40403 – Debian Security Advisory 5306-1
https://notcve.org/view.php?id=CVE-2021-40403
04 Feb 2022 — An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerability. Se presenta una vulnerabilidad de divulgación de información en la funcionalidad pick-and-place rotation parsing de Gerbv versiones 2.7.0 y dev (commit b5f... • https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PTGBC37N2FV7NKOWFVCFMPAFYEPHSB7C • CWE-456: Missing Initialization of a Variable CWE-909: Missing Initialization of Resource •