cbcvebase.
CVE-2018-19492
published 2018-11-23

CVE-2018-19492: An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the…

PriorityP338high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.55%
72.6th percentile
An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo terminal is used as a backend.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiangnuplot< gnuplot 5.4.0+dfsg1-1 (bookworm)gnuplot 5.4.0+dfsg1-1 (bookworm)
gnuplotgnuplot
gnuplotgnuplot>= 0 < 5.4.0+dfsg1-15.4.0+dfsg1-1
gnuplotgnuplot>= 0 < 5.4.0+dfsg1-15.4.0+dfsg1-1
gnuplotgnuplot>= 0 < 5.4.0+dfsg1-15.4.0+dfsg1-1
gnuplotgnuplot>= 0 < 5.4.0+dfsg1-15.4.0+dfsg1-1
gnuplotgnuplot>= 0 < 4.6.6-3ubuntu0.14.6.6-3ubuntu0.1
gnuplotgnuplot>= 0 < 4.6.4-2ubuntu0.1~esm14.6.4-2ubuntu0.1~esm1
gnuplotgnuplot>= 0 < 4.6.6-3ubuntu0.1+esm14.6.6-3ubuntu0.1+esm1
gnuplotgnuplot>= 0 < 5.2.2+dfsg1-2ubuntu1+esm15.2.2+dfsg1-2ubuntu1+esm1
gnuplotgnuplot>= 0 < 5.2.8+dfsg1-2ubuntu0.1~esm15.2.8+dfsg1-2ubuntu0.1~esm1
opensuseleap

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.