{"id":"MGASA-2022-0176","summary":"Updated gerbv packages fix security vulnerability","details":"An information disclosure vulnerability exists in the pick-and-place\nrotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd),\nand Gerbv forked 2.8.0. A specially-crafted pick-and-place file can\nexploit the missing initialization of a structure to leak memory contents.\nAn attacker can provide a malicious file to trigger this vulnerability.\n(CVE-2021-40403)\n","modified":"2026-04-16T00:09:02.044477683Z","published":"2022-05-12T10:24:45Z","upstream":["CVE-2021-40403"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2022-0176.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=30391"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/PTGBC37N2FV7NKOWFVCFMPAFYEPHSB7C/"}],"affected":[{"package":{"name":"gerbv","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/gerbv?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.0-3.1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2022-0176.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}