CVE-2023-35957

Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the decompression function `uncompress`.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tonybybell:gtkwave:3.3.115:*:*:*:*:*:*:*

History

21 Nov 2024, 08:09

Type Values Removed Values Added
References () https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html - () https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html -
References () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1785 - Exploit, Third Party Advisory () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1785 - Exploit, Third Party Advisory

09 Apr 2024, 21:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html -

11 Jan 2024, 17:30

Type Values Removed Values Added
First Time Tonybybell gtkwave
Tonybybell
Summary
  • (es) Existen múltiples vulnerabilidades de desbordamiento de búfer de almacenamiento dinámico en la funcionalidad de análisis VCDATA fstReaderIterBlocks2 de GTKWave 3.3.115. Un archivo .fst especialmente manipulado puede provocar la ejecución de código arbitrario. Una víctima necesitaría abrir un archivo malicioso para activar estas vulnerabilidades. Esta vulnerabilidad se refiere a la función de descompresión "descomprimir".
References () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1785 - () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1785 - Exploit, Third Party Advisory
CPE cpe:2.3:a:tonybybell:gtkwave:3.3.115:*:*:*:*:*:*:*

08 Jan 2024, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1785', 'source': 'talos-cna@cisco.com'}

08 Jan 2024, 15:27

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-08 15:15

Updated : 2024-11-21 08:09


NVD link : CVE-2023-35957

Mitre link : CVE-2023-35957

CVE.ORG link : CVE-2023-35957


JSON object : View

Products Affected

tonybybell

  • gtkwave
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer