Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-9670

Опубликовано: 15 июн. 2017
Источник: debian
EPSS Низкий

Описание

An uninitialized stack variable vulnerability in load_tic_series() in set.c in gnuplot 5.2.rc1 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact when a victim opens a specially crafted file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnuplotfixed5.0.5+dfsg1-7package
gnuplotfixed5.0.5+dfsg1-6+deb9u1stretchpackage
gnuplotnot-affectedjessiepackage
gnuplotnot-affectedwheezypackage
gnuplot5removedpackage
gnuplot5not-affectedjessiepackage

Примечания

  • https://sourceforge.net/p/gnuplot/bugs/1933/

  • The specific CVE is for the uninitialized stack variable fixed via set.c

  • https://bugzilla.suse.com/show_bug.cgi?id=1044638#c5

  • Fixed by: https://github.com/gnuplot/gnuplot/commit/4e39b1d7b274c7d4a69cbaba85ff321264f4457e

  • Introduced by: https://github.com/gnuplot/gnuplot/commit/cd4b777389379598740fc02decff772b0e7bcbd6

  • Crash in a CLI tool, no security impact

EPSS

Процентиль: 43%
0.00208
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

An uninitialized stack variable vulnerability in load_tic_series() in set.c in gnuplot 5.2.rc1 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact when a victim opens a specially crafted file.

CVSS3: 3.3
redhat
больше 8 лет назад

An uninitialized stack variable vulnerability in load_tic_series() in set.c in gnuplot 5.2.rc1 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact when a victim opens a specially crafted file.

CVSS3: 7.8
nvd
больше 8 лет назад

An uninitialized stack variable vulnerability in load_tic_series() in set.c in gnuplot 5.2.rc1 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact when a victim opens a specially crafted file.

CVSS3: 7.8
github
больше 3 лет назад

An uninitialized stack variable vulnerability in load_tic_series() in set.c in gnuplot 5.2.rc1 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact when a victim opens a specially crafted file.

suse-cvrf
больше 5 лет назад

Security update for gnuplot

EPSS

Процентиль: 43%
0.00208
Низкий