PT-2024-12534 · Gtkwave · Gtkwave
Claudio Bozzato
·
Published
2024-01-08
·
Updated
2024-04-09
·
CVE-2023-35962
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GTKWave version 3.3.115
Description
The issue concerns decompression in the
vcd2vzt utility of GTKWave, where multiple OS command injection vulnerabilities exist. These vulnerabilities can be triggered by a specially crafted wave file, potentially leading to arbitrary command execution when a victim opens the malicious file.Recommendations
For GTKWave version 3.3.115, consider disabling the
vcd2vzt utility until a patch is available to prevent potential exploitation. Avoid opening wave files from untrusted sources to minimize the risk of arbitrary command execution.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gtkwave