CVE-2022-23803: Buffer Overflow
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadXYCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23803?
CVE-2022-23803 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2022-23803?
To fix CVE-2022-23803, upgrade KiCad to version 6.0.11 or later for affected installations.
What software versions are affected by CVE-2022-23803?
CVE-2022-23803 affects KiCad EDA versions prior to 6.0.11, as well as various Debian packages lower than specified versions.
What is the attack vector for CVE-2022-23803?
The attack vector for CVE-2022-23803 involves the use of specially-crafted gerber or excellon files designed to exploit the vulnerability.
Can CVE-2022-23803 be exploited remotely?
Yes, CVE-2022-23803 can be exploited remotely if an attacker is able to provide a malicious file to the victim.