Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46122
HistoryApr 01, 2024 - 10:01 p.m.

Arbitrary Code Execution

2024-04-0122:01:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
gtkwave
vulnerability
code execution
software
.fst file

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

Low

EPSS

0.001

Percentile

23.1%

gtkwave is vulnerable to Arbitrary Code Execution. The vulnerability arises from inadequate validation of array indices within the tdelta initialization process.A specially crafted .fst file can exploit these vulnerabilities, leading to arbitrary code execution.

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

Low

EPSS

0.001

Percentile

23.1%