7.8
CVSSv3

CVE-2023-37922

Published: 08/01/2024 Updated: 09/04/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the arbitrary write when triggered via the vcd2lxt2 conversion utility.

Vulnerable Product Search on Vulmon Subscribe to Product

tonybybell gtkwave 3.3.115

Vendor Advisories

Debian Bug report logs - #1060407 Multiple security issues Package: src:gtkwave; Maintainer for src:gtkwave is Debian Electronics Team <pkg-electronics-devel@alioth-listsdebiannet>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 10 Jan 2024 19:39:02 UTC Severity: grave Tags: security, upstream Found i ...