CVE-2022-23946: Buffer Overflow
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23946?
CVE-2022-23946 has a high severity due to its potential to lead to remote code execution.
How do I fix CVE-2022-23946?
To fix CVE-2022-23946, you should upgrade to a patched version of KiCad EDA that addresses this vulnerability.
Which versions of KiCad EDA are affected by CVE-2022-23946?
CVE-2022-23946 affects KiCad EDA version 6.0.1 and below.
Can CVE-2022-23946 be exploited through a specific file type?
Yes, CVE-2022-23946 can be exploited using specially-crafted gerber or excellon files.
What are the risks of not addressing CVE-2022-23946?
Not addressing CVE-2022-23946 can leave systems vulnerable to potential remote code execution attacks.