VYPR
Unrated severityNVD Advisory· Published Jan 8, 2024· Updated Nov 4, 2025

CVE-2023-35970

CVE-2023-35970

Description

Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 chain_table parsing functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the chain_table of the FST_BL_VCDATA_DYN_ALIAS2 section type.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple heap-based buffer overflows in GTKWave 3.3.115's fstReaderIterBlocks2 function allow arbitrary code execution via a crafted .fst file.

Vulnerability

Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 function of GTKWave 3.3.115 when parsing the chain_table of the FST_BL_VCDATA_DYN_ALIAS2 section type in a .fst file. These flaws are classified under CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). A specially crafted .fst file can trigger the overflow, leading to arbitrary code execution. The vulnerable version confirmed is GTKWave 3.3.115 [1].

Exploitation

An attacker can exploit these vulnerabilities by crafting a malicious .fst file and convincing a victim to open it. The victim may open the file using the GTKWave GUI (e.g., by double-clicking the file or via email attachment, as GTKWave registers mime types for supported extensions) or via command-line tools [1]. No authentication or special privileges are required; only user interaction (opening the file) is necessary [1].

Impact

Successful exploitation allows an attacker to achieve arbitrary code execution with the privileges of the victim. This could lead to full compromise of the system's confidentiality, integrity, and availability (CVSSv3 score 7.8, High) [1].

Mitigation

As of the publication date (2024-01-08), no patch or fixed version has been released. The vendor was confirmed to be vulnerable. Users should avoid opening .fst files from untrusted sources and consider using alternative tools or up-to-date versions if a patch becomes available [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • GTKWave/GTKWavellm-fuzzy
    Range: =3.3.115
  • GTKWave/GTKWavev5
    Range: 3.3.115

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.