CVE-2023-36747
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2023-36747 is a buffer overflow vulnerability affecting the GTKWave 3.3.115 software. Multiple heap-based buffer overflows can occur in the fstReaderIterBlocks2 function of fstWritex due to an issue with the handling of the 'len' parameter when 'beg_time' does not align with the start of the time table. A specially crafted .fst file can cause memory corruption if opened by a victim. These vulnerabilities pose a risk of arbitrary code execution or denial-of-service attacks. It is highly recommended that users update to a patched version of GTKWave to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.