CVE-2021-40391 log

Source
Severity Medium
Remote Yes
Type Arbitrary code execution
Description
An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv before version 2.8.0. A specially-crafted drill file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Group Package Affected Fixed Severity Status Ticket
AVG-2534 gerbv 2.7.0-2 2.8.1-1 Medium Fixed
References
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1402
https://github.com/gerbv/gerbv/issues/30
https://github.com/gerbv/gerbv/pull/35
https://github.com/gerbv/gerbv/commit/672214abb47a802fc000125996e6e0a46c623a4e