Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian: DSA-5653-1 Critical: gtkwave Code Execution Issues

debian
Calendar Grey April 3, 2024
Debian Logo
Debian Security Advisory DSA-5654-2 addresses critical vulnerabilities in gnome-shell package arising from several privilege escalation issues.
Claudio Bozzato discovered multiple security issues in gtkwave, a file waveform viewer for VCD (Value Change Dump) files, which may result in the execution of arbitrary code if mal...

Summary

Claudio Bozzato discovered multiple security issues in gtkwave, a file
waveform viewer for VCD (Value Change Dump) files, which may result in the
execution of arbitrary code if malformed files are opened.

For the oldstable distribution (bullseye), these problems have been fixed
in version 3.3.104+really3.3.118-0+deb11u1.

For the stable distribution (bookworm), these problems have been fixed in
version 3.3.118-0.1~deb12u1.

We recommend that you upgrade your gtkwave packages.

For the detailed security status of gtkwave please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/gtkwave

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: gtkwave
CVE ID: CVE-2023-32650 CVE-2023-34087 CVE-2023-34436 CVE-2023-35004

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here