CVE-2023-33863
an integer overflow that results in a heap-based buffer overflow
that might be exploitable by a remote attacker to execute arbitrary
code on the machine that runs RenderDoc
CVE-2023-33864
an integer underflow that results in a heap-based buffer overflow
that might be exploitable by a remote attacker to execute arbitrary
code on the machine that runs RenderDoc.
CVE-2023-33865
a symlink vulnerability that might be exploitable by a unprivileged
local attacker to obtain the privileges of the user who runs
RenderDoc.
For Debian 10 buster, these problems have been fixed in version
1.2+dfsg-2+deb10u1.
We recommend that you upgrade your renderdoc packages.
For the detailed security status of renderdoc please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/renderdoc
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
Get the latest Linux and open source security news straight to your inbox.