CVE-2021-40403 is an information disclosure vulnerability in Gerbv versions 2.7.0, dev (commit b5f1eacd), and forked 2.8.0, affecting Debian and Fedora distributions. It allows an attacker to leak memory contents by providing a specially crafted pick-and-place file that exploits missing structure initialization. Rated 6.3 Medium (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N), this vulnerability requires user interaction (UI:R) and local access (AV:L) to achieve high confidentiality impact (C:H). While not actively exploited in the wild and lacking public exploit code, it has garnered some community discussion and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.7.0CPE matchmatch criteria | cpe:2.3:a:gerbv_project:gerbv:2.7.0:-:*:*:*:*:*:* | ||
2.8.0CPE matchmatch criteria | cpe:2.3:a:gerbv_project:gerbv:2.8.0:forked_dev:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.