Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-19490

Опубликовано: 23 нояб. 2018
Источник: debian

Описание

An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnuplotfixed5.4.0+dfsg1-1package
gnuplot5removedpackage

Примечания

  • https://sourceforge.net/p/gnuplot/bugs/2093/

  • https://sourceforge.net/p/gnuplot/gnuplot-main/ci/d5020716834582b20a5e12cdd49f39ee4f9dd949/ (5.4.rc1)

  • No security impact, gnuplot can execute arbitrary commands and need to come from a trusted source,

  • see README.Debian.security (added in 5.2.6)

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 7 лет назад

An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.

CVSS3: 3.3
redhat
около 7 лет назад

An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.

CVSS3: 7.8
nvd
около 7 лет назад

An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.

CVSS3: 7.8
github
больше 3 лет назад

An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.

suse-cvrf
почти 7 лет назад

Security update for gnuplot