An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot postscript terminal is used as a backend.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-gnuplot | Feb 19, 2019 | Nov 23, 2018 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-gnuplothuawei-euleros-2_0_sp8-upgrade-gnuplot-common | Aug 31, 2020 | Nov 23, 2018 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-image-gnuplot-5-4-2-11-4-39-0-1-107-0 | Nov 17, 2021 | Nov 23, 2018 | |
| Suse | — | suse-upgrade-gnuplotsuse-upgrade-gnuplot-doc | Apr 17, 2019 | Nov 23, 2018 |
| Ubuntu | ubuntu-pro-upgrade-gnuplotubuntu-pro-upgrade-gnuplot-dataubuntu-pro-upgrade-gnuplot-noxubuntu-pro-upgrade-gnuplot-qtubuntu-pro-upgrade-gnuplot-texubuntu-pro-upgrade-gnuplot-x11ubuntu-upgrade-gnuplotubuntu-upgrade-gnuplot-dataubuntu-upgrade-gnuplot-noxubuntu-upgrade-gnuplot-qtubuntu-upgrade-gnuplot-texubuntu-upgrade-gnuplot-x11 | Sep 26, 2020 | Nov 23, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub