7.8
CVSSv3

CVE-2023-35989

Published: 08/01/2024 Updated: 09/04/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

An integer overflow vulnerability exists in the LXT2 zlib block allocation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

tonybybell gtkwave 3.3.115

Vendor Advisories

Debian Bug report logs - #1060407 Multiple security issues Package: src:gtkwave; Maintainer for src:gtkwave is Debian Electronics Team <pkg-electronics-devel@alioth-listsdebiannet>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 10 Jan 2024 19:39:02 UTC Severity: grave Tags: security, upstream Found i ...