CVE-2022-23947: Buffer Overflow
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23947?
CVE-2022-23947 is a critical vulnerability that can lead to code execution due to a stack-based buffer overflow.
How do I fix CVE-2022-23947?
To fix CVE-2022-23947, update KiCad EDA to version 6.0.11 or later.
What is the affected software for CVE-2022-23947?
CVE-2022-23947 affects KiCad EDA versions 6.0.1 and prior, as well as certain Debian and Fedora releases.
Can CVE-2022-23947 be exploited remotely?
Yes, CVE-2022-23947 can be exploited remotely by an attacker providing a specially-crafted gerber or excellon file.
What kind of attack can CVE-2022-23947 enable?
CVE-2022-23947 can enable arbitrary code execution on the target system when exploited.