PT-2024-2951 · Gtkwave · Gtkwave

Claudio Bozzato

·

Published

2024-01-08

·

Updated

2024-04-09

·

CVE-2023-34087

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GTKWave version 3.3.115
Description The issue is related to an improper array index validation vulnerability in the EVCD var len parsing functionality. This can lead to arbitrary code execution when a victim opens a specially crafted .evcd file. The vulnerability is associated with a buffer overflow in memory.
Recommendations For GTKWave version 3.3.115, consider avoiding the use of the EVCD var len parsing functionality until a patch is available. As a temporary workaround, restrict the opening of .evcd files from untrusted sources to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-03118
CVE-2023-34087
DLA-3785-1
DSA-5653-1

Affected Products

Gtkwave