Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46258
HistoryApr 07, 2024 - 1:05 p.m.

Integer Underflow

2024-04-0713:05:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
integer underflow
gtkwave 3.3.115
lxt2 file
memory corruption
shift operation

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

21.5%

GTKWave 3.3.115 is vulnerable to an Integer Underflow. The vulnerability is caused due to a defect in the LXT2 lxt2_rd_iter_radix shift operation functionality when performing the left shift operation. A specially crafted .lxt2 file can lead to memory corruption when the victim opens the file.

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

Low

EPSS

0.001

Percentile

21.5%