An integer overflow vulnerability exists in the LXT2 zlib block allocation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3785-1 gtkwave security update
Debian DSA Debian DSA DSA-5653-1 gtkwave security update
EUVD EUVD EUVD-2023-39973 An integer overflow vulnerability exists in the LXT2 zlib block allocation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Nov 2025 19:30:00 +0000


Tue, 17 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2025-11-04T18:15:06.245Z

Reserved: 2023-07-31T19:23:15.979Z

Link: CVE-2023-35989

cve-icon Vulnrichment

Updated: 2025-11-04T18:15:06.245Z

cve-icon NVD

Status : Modified

Published: 2024-01-08T15:15:12.800

Modified: 2025-11-04T19:15:45.393

Link: CVE-2023-35989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.