PT-2024-12583 · Gtkwave · Gtkwave

Claudio Bozzato

·

Published

2024-01-08

·

Updated

2024-04-09

·

CVE-2023-36746

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GTKWave version 3.3.115
Description The issue is related to multiple heap-based buffer overflow vulnerabilities in the fstReaderIterBlocks2 and fstWritex len functionality. These vulnerabilities can be triggered by a specially crafted .fst file, leading to memory corruption when a victim opens the malicious file. The problem concerns the handling of len in fstWritex when parsing the time table.
Recommendations For GTKWave version 3.3.115, consider avoiding the use of the fstWritex function with untrusted .fst files until a patch is available. As a temporary workaround, restrict the opening of .fst files from untrusted sources to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2023-36746
DLA-3785-1
DSA-5653-1

Affected Products

Gtkwave