CVE-2022-23804: Buffer Overflow
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23804?
CVE-2022-23804 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2022-23804?
To mitigate CVE-2022-23804, upgrade KiCad to version 6.0.11 or later, or apply relevant patches provided by your distribution.
What software versions are affected by CVE-2022-23804?
CVE-2022-23804 affects KiCad version 6.0.1 and earlier, as well as specific versions of the software on Debian and Fedora.
Can CVE-2022-23804 be exploited remotely?
Yes, CVE-2022-23804 can be exploited remotely by an attacker using specially-crafted gerber or excellon files.
What type of vulnerability is CVE-2022-23804?
CVE-2022-23804 is a stack-based buffer overflow vulnerability.