ZeroHour

CVE-2018-19491

PoC
CVSS 3.0
7.8 high
EPSS
2%p77
Published
()
Modified
Description

An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot postscript terminal is used as a backend.

Vendors
gnuplotdebianopensuse
Products
gnuplot, debian linux, leap
Weakness
CWE-119
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.