CVE-2018-19490
23.11.2018, 17:29
An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.Enginsight
Vendor | Product | Version |
---|---|---|
gnuplot | gnuplot | 5.2.5 |
debian | debian_linux | 8.0 |
opensuse | leap | 15.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
gnuplot |
| ||||||||||||||||||||||||||||||
gnuplot5 |
|
Common Weakness Enumeration
References