CVE-2023-35704

Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the fstReaderVarint32WithSkip function.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tonybybell:gtkwave:3.3.115:*:*:*:*:*:*:*

History

21 Nov 2024, 08:08

Type Values Removed Values Added
References () https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html - () https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html -
References () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1783 - Exploit, Third Party Advisory () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1783 - Exploit, Third Party Advisory

09 Apr 2024, 21:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html -

16 Jan 2024, 17:34

Type Values Removed Values Added
First Time Tonybybell gtkwave
Tonybybell
References () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1783 - () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1783 - Exploit, Third Party Advisory
CWE CWE-787
Summary
  • (es) Existen múltiples vulnerabilidades de desbordamiento de búfer en la región stack de la memoria en la funcionalidad variante FST LEB128 de GTKWave 3.3.115. Un archivo .fst especialmente manipulado puede provocar la ejecución de código arbitrario. Una víctima necesitaría abrir un archivo malicioso para activar estas vulnerabilidades. Esta vulnerabilidad afecta a la función fstReaderVarint32WithSkip.
CPE cpe:2.3:a:tonybybell:gtkwave:3.3.115:*:*:*:*:*:*:*

08 Jan 2024, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1783', 'source': 'talos-cna@cisco.com'}

08 Jan 2024, 15:27

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-08 15:15

Updated : 2024-11-21 08:08


NVD link : CVE-2023-35704

Mitre link : CVE-2023-35704

CVE.ORG link : CVE-2023-35704


JSON object : View

Products Affected

tonybybell

  • gtkwave
CWE
CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write