An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gnuplot | Feb 19, 2019 | Nov 23, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade gnuplotUpgrade gnuplot-common | Aug 31, 2020 | Nov 23, 2018 |
| Oracle Solaris | — | Upgrade image/gnuplot to version 5.4.2-11.4.39.0.1.107.0 on Solaris 11.4 | Nov 17, 2021 | Nov 23, 2018 |
| Suse | — | Upgrade gnuplot-docUpgrade gnuplot | Apr 17, 2019 | Nov 23, 2018 |
| Ubuntu | — | Upgrade gnuplot-data (Ubuntu Pro)Upgrade gnuplot-dataUpgrade gnuplot-qt (Ubuntu Pro)Upgrade gnuplot (Ubuntu Pro)Upgrade gnuplot-x11Upgrade gnuplot-x11 (Ubuntu Pro)Upgrade gnuplot-qtUpgrade gnuplot-tex (Ubuntu Pro)Upgrade gnuplotUpgrade gnuplot-texUpgrade gnuplot-nox (Ubuntu Pro)Upgrade gnuplot-nox | Sep 26, 2020 | Nov 23, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub