Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-19490

Опубликовано: 19 нояб. 2018
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.

Отчет

Gnuplot allows for trivial execution of arbitrary commands from within gnuplot files by design. As such, gnuplot files should be considered as inherently dangerous and users should only execute files from trusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gnuplotNot affected
Red Hat Enterprise Linux 6gnuplotNot affected
Red Hat Enterprise Linux 7gnuplotNot affected
Red Hat Enterprise Linux 8gnuplotNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1656174gnuplot: heap-based buffer overflow in df_generate_ascii_array_entry

EPSS

Процентиль: 85%
0.02776
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 8 лет назад

An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.

CVSS3: 7.8
nvd
почти 8 лет назад

An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.

CVSS3: 7.8
debian
почти 8 лет назад

An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue all ...

CVSS3: 7.8
github
больше 4 лет назад

An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.

suse-cvrf
больше 7 лет назад

Security update for gnuplot

EPSS

Процентиль: 85%
0.02776
Низкий

3.3 Low

CVSS3