Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the arbitrary write when triggered via the vcd2vzt conversion utility.
The product does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed using an index or pointer, such as memory or files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gtkwave | Tonybybell | 3.3.115 (including) | 3.3.115 (including) |
Gtkwave | Ubuntu | bionic | * |
Gtkwave | Ubuntu | lunar | * |
Gtkwave | Ubuntu | mantic | * |
Gtkwave | Ubuntu | trusty | * |
Gtkwave | Ubuntu | xenial | * |