VYPR
Unrated severityNVD Advisory· Published Jan 8, 2024· Updated Nov 4, 2025

CVE-2023-37420

CVE-2023-37420

Description

Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave 3.3.115. A specially crafted .vcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the out-of-bounds write when triggered via the vcd2lxt conversion utility.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple out-of-bounds write vulnerabilities in GTKWave 3.3.115's VCD parsing allow arbitrary code execution via a crafted .vcd file.

Vulnerability

Multiple out-of-bounds write vulnerabilities exist in the VCD parse_valuechange portdump functionality of GTKWave version 3.3.115 [1]. The flaw resides in the vcd_parse function used by the vcd2lxt conversion utility and other components. A specially crafted .vcd file triggers an out-of-bounds write (CWE-787) during parsing, leading to memory corruption [1].

Exploitation

An attacker must convince a victim to open a malicious .vcd file, either through the GTKWave GUI or by using a command-line conversion tool such as vcd2lxt [1]. No authentication or special privileges are required; the victim only needs to process the crafted file. The vulnerability is triggered automatically during the parsing of the value change dump data [1].

Impact

Successful exploitation allows an attacker to achieve arbitrary code execution with the privileges of the victim [1]. This compromises confidentiality, integrity, and availability, as reflected by the CVSSv3 score of 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) [1].

Mitigation

As of the advisory publication date (January 8, 2024), no official patch has been released by the vendor for GTKWave 3.3.115 [1]. Users are advised to avoid opening untrusted .vcd files and to monitor for future updates from the GTKWave project. No workaround is documented in the available reference [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • GTKWave/GTKWavellm-fuzzy
    Range: = 3.3.115
  • GTKWave/GTKWavev5
    Range: 3.3.115

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.