An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-gnuplot | Feb 19, 2019 | Nov 23, 2018 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-gnuplothuawei-euleros-2_0_sp8-upgrade-gnuplot-common | Aug 31, 2020 | Nov 23, 2018 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-image-gnuplot-5-4-2-11-4-39-0-1-107-0 | Nov 17, 2021 | Nov 23, 2018 | |
| Suse | — | suse-upgrade-gnuplotsuse-upgrade-gnuplot-doc | Apr 17, 2019 | Nov 23, 2018 |
| Ubuntu | ubuntu-pro-upgrade-gnuplotubuntu-pro-upgrade-gnuplot-dataubuntu-pro-upgrade-gnuplot-noxubuntu-pro-upgrade-gnuplot-qtubuntu-pro-upgrade-gnuplot-texubuntu-pro-upgrade-gnuplot-x11ubuntu-upgrade-gnuplotubuntu-upgrade-gnuplot-dataubuntu-upgrade-gnuplot-noxubuntu-upgrade-gnuplot-qtubuntu-upgrade-gnuplot-texubuntu-upgrade-gnuplot-x11 | Sep 26, 2020 | Nov 23, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub