Vulnerabilities > CVE-2023-4508 - Access of Uninitialized Pointer vulnerability in Gerbv Project Gerbv
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, can cause a crash and cause denial-of-service with a specially crafted Gerber RS-274X file.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4508
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4508
- https://github.com/gerbv/gerbv/commit/5517e22250e935dc7f86f64ad414aeae3dbcb36a
- https://github.com/gerbv/gerbv/commit/5517e22250e935dc7f86f64ad414aeae3dbcb36a
- https://github.com/gerbv/gerbv/issues/191
- https://github.com/gerbv/gerbv/issues/191