A user able to control file input to Gerbv, between versions 2.4.0 and 2.10.0, can cause a crash and cause denial-of-service with a specially crafted Gerber RS-274X file.
0Unknown introduced version / All previous versions are affected
Fixed
2.6.0-1ubuntu0.16.04.1~esm2
Affected versions
2.*
2.6.0-1
2.6.0-1ubuntu0.16.04.1~esm1
Ecosystem specific
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "2.6.0-1ubuntu0.16.04.1~esm2",
"binary_name": "gerbv"
}
],
"priority_reason": "Impact is only a denial of service."
}
0Unknown introduced version / All previous versions are affected
Fixed
2.6.1-3ubuntu0.1~esm2
Affected versions
2.*
2.6.1-2
2.6.1-3
2.6.1-3ubuntu0.1~esm1
Ecosystem specific
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "2.6.1-3ubuntu0.1~esm2",
"binary_name": "gerbv"
}
],
"priority_reason": "Impact is only a denial of service."
}
0Unknown introduced version / All previous versions are affected
Fixed
2.7.0-1ubuntu0.2
Affected versions
2.*
2.7.0-1
2.7.0-1ubuntu0.1
Ecosystem specific
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "2.7.0-1ubuntu0.2",
"binary_name": "gerbv"
}
],
"priority_reason": "Impact is only a denial of service."
}
0Unknown introduced version / All previous versions are affected
Fixed
2.8.2-1ubuntu0.1~esm2
Affected versions
2.*
2.7.0-2
2.7.1-1
2.8.0-1
2.8.1-1
2.8.2-1
2.8.2-1ubuntu0.1~esm1
Ecosystem specific
{
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
"binaries": [
{
"binary_version": "2.8.2-1ubuntu0.1~esm2",
"binary_name": "gerbv"
}
],
"priority_reason": "Impact is only a denial of service."
}