CVE Vulnerabilities

CVE-2023-37923

Published: Jan 08, 2024 | Modified: Apr 09, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Multiple arbitrary write vulnerabilities exist in the VCD sorted bsearch functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the arbitrary write when triggered via the vcd2lxt conversion utility.

Affected Software

Name Vendor Start Version End Version
Gtkwave Tonybybell 3.3.115 (including) 3.3.115 (including)
Gtkwave Ubuntu bionic *
Gtkwave Ubuntu lunar *
Gtkwave Ubuntu mantic *
Gtkwave Ubuntu trusty *
Gtkwave Ubuntu xenial *

References