Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-19492

Опубликовано: 19 нояб. 2018
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo terminal is used as a backend.

Отчет

Gnuplot allows for trivial execution of arbitrary commands from within gnuplot files by design. As such, gnuplot files should be considered as inherently dangerous and users should only execute files from trusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gnuplotNot affected
Red Hat Enterprise Linux 6gnuplotNot affected
Red Hat Enterprise Linux 7gnuplotNot affected
Red Hat Enterprise Linux 8gnuplotNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1656183gnuplot: buffer overflow in cairotrm_options function

EPSS

Процентиль: 38%
0.00165
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 7 лет назад

An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo terminal is used as a backend.

CVSS3: 7.8
nvd
около 7 лет назад

An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo terminal is used as a backend.

CVSS3: 7.8
debian
около 7 лет назад

An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allo ...

CVSS3: 7.8
github
больше 3 лет назад

An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo terminal is used as a backend.

suse-cvrf
почти 7 лет назад

Security update for gnuplot

EPSS

Процентиль: 38%
0.00165
Низкий

3.3 Low

CVSS3