#VU85120 Improper Validation of Array Index in GTKWave - CVE-2023-34087
Published: January 9, 2024
GTKWave
gtkwave
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error in the EVCD var len parsing functionality. A remote attacker can
create a specially crafted .evcd file, trick the victim into opening it
using the affected software, trigger an array index error and execute arbitrary code on the system.