Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-38583
HistoryJan 08, 2024 - 12:00 a.m.

CVE-2023-38583

2024-01-0800:00:00
ubuntu.com
ubuntu.com
17
stack-based buffer overflow
gtkwave 3.3.115
arbitrary code execution
malicious file
lxt2 file
unix

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

23.1%

A stack-based buffer overflow vulnerability exists in the LXT2
lxt2_rd_expand_integer_to_bits function of GTKWave 3.3.115. A specially
crafted .lxt2 file can lead to arbitrary code execution. A victim would
need to open a malicious file to trigger this vulnerability.

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

23.1%