cbcvebase.
CVE-2018-19490
published 2018-11-23

CVE-2018-19490: An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data…

PriorityP338high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.55%
72.4th percentile
An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is passed to the plot function.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiangnuplot< gnuplot 5.4.0+dfsg1-1 (bookworm)gnuplot 5.4.0+dfsg1-1 (bookworm)
gnuplotgnuplot
gnuplotgnuplot>= 0 < 5.4.0+dfsg1-15.4.0+dfsg1-1
gnuplotgnuplot>= 0 < 5.4.0+dfsg1-15.4.0+dfsg1-1
gnuplotgnuplot>= 0 < 5.4.0+dfsg1-15.4.0+dfsg1-1
gnuplotgnuplot>= 0 < 5.4.0+dfsg1-15.4.0+dfsg1-1
gnuplotgnuplot>= 0 < 4.6.6-3ubuntu0.14.6.6-3ubuntu0.1
gnuplotgnuplot>= 0 < 4.6.4-2ubuntu0.1~esm14.6.4-2ubuntu0.1~esm1
gnuplotgnuplot>= 0 < 4.6.6-3ubuntu0.1+esm14.6.6-3ubuntu0.1+esm1
gnuplotgnuplot>= 0 < 5.2.2+dfsg1-2ubuntu1+esm15.2.2+dfsg1-2ubuntu1+esm1
gnuplotgnuplot>= 0 < 5.2.8+dfsg1-2ubuntu0.1~esm15.2.8+dfsg1-2ubuntu0.1~esm1
opensuseleap

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.