PT-2024-12536 · Gtkwave · Gtkwave

Claudio Bozzato

·

Published

2024-01-08

·

Updated

2024-04-09

·

CVE-2023-35964

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GTKWave version 3.3.115
Description The issue concerns decompression in the vcd2lxt utility of GTKWave, where multiple OS command injection vulnerabilities exist. These vulnerabilities can be triggered by a specially crafted wave file, potentially leading to arbitrary command execution when a victim opens the malicious file.
Recommendations For GTKWave version 3.3.115, consider avoiding the use of the vcd2lxt utility until a fix is available, or refrain from opening untrusted wave files to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-35964
DLA-3785-1
DSA-5653-1

Affected Products

Gtkwave