An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gnuplot | Feb 19, 2019 | Nov 23, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade gnuplot-commonUpgrade gnuplot | Aug 31, 2020 | Nov 23, 2018 |
| Oracle Solaris | — | Upgrade image/gnuplot to version 5.4.2-11.4.39.0.1.107.0 on Solaris 11.4 | Nov 17, 2021 | Nov 23, 2018 |
| Suse | — | Upgrade gnuplot-docUpgrade gnuplot | Apr 17, 2019 | Nov 23, 2018 |
| Ubuntu | — | Upgrade gnuplot-texUpgrade gnuplot-tex (Ubuntu Pro)Upgrade gnuplot-nox (Ubuntu Pro)Upgrade gnuplot-qtUpgrade gnuplot-x11 (Ubuntu Pro)Upgrade gnuplotUpgrade gnuplot-noxUpgrade gnuplot-x11Upgrade gnuplot-data (Ubuntu Pro)Upgrade gnuplot-dataUpgrade gnuplot (Ubuntu Pro)Upgrade gnuplot-qt (Ubuntu Pro) | Sep 26, 2020 | Nov 23, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub