CVE-2023-38583

NameCVE-2023-38583
DescriptionA stack-based buffer overflow vulnerability exists in the LXT2 lxt2_rd_expand_integer_to_bits function of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1060407

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gtkwave (PTS)buster3.3.98-1vulnerable
bullseye3.3.104-2vulnerable
bookworm3.3.114-2vulnerable
sid3.3.116-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gtkwavesource(unstable)(unfixed)1060407

Notes

https://talosintelligence.com/vulnerability_reports/TALOS-2023-1827

Search for package or bug name: Reporting problems