Improper Validation of Array Index in GTKWave - CVE-2023-34087
Published: January 9, 2024
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error in the EVCD var len parsing functionality. A remote attacker can
create a specially crafted .evcd file, trick the victim into opening it
using the affected software, trigger an array index error and execute arbitrary code on the system.
Affected software
Debian Linux
Fedora
gtkwave (Debian package)
gtkwave
How to mitigate CVE-2023-34087
gtkwave (Debian package) - addressed in versions 3.3.104+really3.3.118-0+deb11u1, 3.3.118-0.1~deb12u1
gtkwave - addressed in versions 3.3.118-1.el7, 3.3.118-1.el8, 3.3.118-1.el9, 3.3.118-1.fc38, 3.3.118-1.fc39