PT-2024-12534 · Gtkwave · Gtkwave

Claudio Bozzato

·

Published

2024-01-08

·

Updated

2024-04-09

·

CVE-2023-35962

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GTKWave version 3.3.115
Description The issue concerns decompression in the vcd2vzt utility of GTKWave, where multiple OS command injection vulnerabilities exist. These vulnerabilities can be triggered by a specially crafted wave file, potentially leading to arbitrary command execution when a victim opens the malicious file.
Recommendations For GTKWave version 3.3.115, consider disabling the vcd2vzt utility until a patch is available to prevent potential exploitation. Avoid opening wave files from untrusted sources to minimize the risk of arbitrary command execution.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-35962
DLA-3785-1
DSA-5653-1

Affected Products

Gtkwave