CVE-2023-35969

Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the chain_table of `FST_BL_VCDATA` and `FST_BL_VCDATA_DYN_ALIAS` section types.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tonybybell:gtkwave:3.3.115:*:*:*:*:*:*:*

History

09 Apr 2024, 21:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/04/msg00007.html -

16 Jan 2024, 17:34

Type Values Removed Values Added
CPE cpe:2.3:a:tonybybell:gtkwave:3.3.115:*:*:*:*:*:*:*
CWE CWE-787
Summary
  • (es) Existen múltiples vulnerabilidades de desbordamiento de búfer de almacenamiento dinámico en la funcionalidad de análisis fstReaderIterBlocks2 chain_table de GTKWave 3.3.115. Un archivo .fst especialmente manipulado puede provocar la ejecución de código arbitrario. Una víctima necesitaría abrir un archivo malicioso para activar estas vulnerabilidades. Esta vulnerabilidad se refiere a chain_table de los tipos de sección `FST_BL_VCDATA` y `FST_BL_VCDATA_DYN_ALIAS`.
First Time Tonybybell
Tonybybell gtkwave
References () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1789 - () https://talosintelligence.com/vulnerability_reports/TALOS-2023-1789 - Exploit, Third Party Advisory

08 Jan 2024, 18:15

Type Values Removed Values Added
References
  • {'url': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1789', 'source': 'talos-cna@cisco.com'}

08 Jan 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-08 15:15

Updated : 2024-04-09 21:15


NVD link : CVE-2023-35969

Mitre link : CVE-2023-35969

CVE.ORG link : CVE-2023-35969


JSON object : View

Products Affected

tonybybell

  • gtkwave
CWE
CWE-787

Out-of-bounds Write

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer