Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25412

Опубликовано: 16 сент. 2020
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution.

A flaw was found in gnuplot. An execution path from com_line() in command.c results in strncpy() being called with an incorrect length, causing an out-of-bounds write. A local attacker could exploit this flaw by passing a specially crafted input file to gnuplot. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

gnuplot as shipped with Red Hat Enterprise Linux 5, 6, 7, and 8 is not affected because the vulnerable code was introduced in a subsequent version of gnuplot.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gnuplotNot affected
Red Hat Enterprise Linux 6gnuplotNot affected
Red Hat Enterprise Linux 7gnuplotNot affected
Red Hat Enterprise Linux 8gnuplotNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1882322gnuplot: out-of-bounds-write from strncpy() may lead to arbitrary code execution

EPSS

Процентиль: 69%
0.00614
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution.

CVSS3: 9.8
nvd
больше 5 лет назад

com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution.

CVSS3: 9.8
debian
больше 5 лет назад

com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write ...

CVSS3: 9.8
github
больше 3 лет назад

gnuplot 5.4 is affected by a segmentation fault in com_line () at command.c, which may result in context-dependent arbitrary code execution.

EPSS

Процентиль: 69%
0.00614
Низкий

7.8 High

CVSS3