CVE Vulnerabilities

CVE-2023-37921

Incorrect Access of Indexable Resource ('Range Error')

Published: Jan 08, 2024 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the arbitrary write when triggered via the vcd2vzt conversion utility.

Weakness

The product does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed using an index or pointer, such as memory or files.

Affected Software

Name Vendor Start Version End Version
Gtkwave Tonybybell 3.3.115 (including) 3.3.115 (including)
Gtkwave Ubuntu bionic *
Gtkwave Ubuntu lunar *
Gtkwave Ubuntu mantic *
Gtkwave Ubuntu trusty *
Gtkwave Ubuntu xenial *

References