7.8
CVSSv3

CVE-2023-37416

Published: 08/01/2024 Updated: 09/04/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the GUI's legacy VCD parsing code.

Vulnerable Product Search on Vulmon Subscribe to Product

tonybybell gtkwave 3.3.115

Vendor Advisories

Debian Bug report logs - #1060407 Multiple security issues Package: src:gtkwave; Maintainer for src:gtkwave is Debian Electronics Team <pkg-electronics-devel@alioth-listsdebiannet>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 10 Jan 2024 19:39:02 UTC Severity: grave Tags: security, upstream Found i ...